VDB
Sign up
HIGH7.7

GHSA-8j34-9876-pvfq

Hugo can execute a binary from the current directory on Windows

Quick fix

GHSA-8j34-9876-pvfq — github.com/gohugoio/hugo: upgrade to the fixed version with the command below.

go get github.com/gohugoio/hugo@v0.79.1

Details

## Impact

Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%PATH%` on Windows. However, if a malicious file with the same name (`exe` or `bat`) is found in the current working directory at the time of running `hugo`, the malicious command will be invoked instead of the system one.

Windows users who run `hugo` inside untrusted Hugo sites are affected.

## Patches Users should upgrade to Hugo v0.79.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/gohugoio/hugo
Introduced in: 0Fixed in: 0.79.1
Fixgo get github.com/gohugoio/hugo@v0.79.1

References