Hugo: XSS via unescaped code-fence language in default code block renderer
Package
Affected versions
>= 0.60.0, < 0.163.3
Patched versions
0.163.3
Description
Published to the GitHub Advisory Database
Jun 19, 2026
Reviewed
Jun 19, 2026
Last updated
Jun 19, 2026
Hugo's default code-block renderer wrote the Markdown code-fence language / info-string into the
<code class="language-…" data-lang="…">wrapper without HTML escaping. A fence info-string containing a quote and a<script>payload breaks out of the attribute and injects a live script element.This is not an issue if you fully trust every file under /content and every content adapter you load.
References