MEDIUM6.1
GHSA-ppf8-hhpp-f5hj
Hugo Markdown titles do not escaped in internal render hooks
Quick fix
GHSA-ppf8-hhpp-f5hj — github.com/gohugoio/hugo: upgrade to the fixed version with the command below.
go get github.com/gohugoio/hugo@v0.125.3Details
### Impact
Title argument in Markdown for links and images not escaped in internal render hooks. Impacted are Hugo users who have these hooks enabled and do not trust their Markdown content files.
### Patches
Patched in v0.125.3.
### Workarounds
Replace with user defined templates or disable the internal templates: https://gohugo.io/getting-started/configuration-markup/#renderhooksimageenabledefault
### References
https://github.com/gohugoio/hugo/releases/tag/v0.125.3
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gohugoio/hugo
Introduced in:
0.123.0Fixed in: 0.125.3Fix
go get github.com/gohugoio/hugo@v0.125.3References
- https://github.com/gohugoio/hugo/security/advisories/GHSA-ppf8-hhpp-f5hj[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-32875[ADVISORY]
- https://github.com/gohugoio/hugo/commit/15a4b9b33715887001f6eff30721d41c0d4cfdd1[WEB]
- https://github.com/gohugoio/hugo[PACKAGE]
- https://github.com/gohugoio/hugo/releases/tag/v0.125.3[WEB]
- https://gohugo.io/getting-started/configuration-markup/#renderhooksimageenabledefault[WEB]
- https://pkg.go.dev/vuln/GO-2024-2747[WEB]