logoalt Hacker News

vntoktoday at 6:44 PM2 repliesview on HN

Sorry in advance if you were joking, but for readers who aren't in the know: Hugo had, in fact, two 9.3 CVSS vulnerabilities just 11 days ago...

https://app.opencve.io/cve/CVE-2026-89259

https://app.opencve.io/cve/CVE-2026-89258


Replies

BadBadJellyBeantoday at 10:23 PM

I have full control over the inputs for hugo and the output is pure static HTML. It's better if there are no CVEs but I really don't sweat these. My Hugo template runs 100% pure CSS and no JS.

aboundtoday at 6:54 PM

To be clear, those are CVEs in the tooling, not in the generated static sites. Not great, but very different from this WordPress CVE