HIGH7.7
GHSA-8j34-9876-pvfq
Hugo can execute a binary from the current directory on Windows
Quick fix
GHSA-8j34-9876-pvfq — github.com/gohugoio/hugo: upgrade to the fixed version with the command below.
go get github.com/gohugoio/hugo@v0.79.1Details
## Impact
Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%PATH%` on Windows. However, if a malicious file with the same name (`exe` or `bat`) is found in the current working directory at the time of running `hugo`, the malicious command will be invoked instead of the system one.
Windows users who run `hugo` inside untrusted Hugo sites are affected.
## Patches Users should upgrade to Hugo v0.79.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gohugoio/hugo
Introduced in:
0Fixed in: 0.79.1Fix
go get github.com/gohugoio/hugo@v0.79.1