An open index of dependabot pull requests across open source projects.

github.com/gohugoio/hugo

Ecosystem:
go
Package URL:
pkg:golang/github.com/gohugoio/hugo
Total PRs:
250 Dependabot PRs
Latest PR:
14 days ago
Unique Repositories:
46 repositories
Unique Repos (30 days):
3 repositories
Security Advisories
Hugo can execute a binary from the current directory on Windows
GHSA-8j34-9876-pvfq CVE-2020-26284 HIGH published almost 5 years ago • updated 5 days ago
## Impact Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%...
Hugo: Certain markdown links are not properly escaped
GHSA-mcv8-8m8x-48pg CVE-2026-35166 MODERATE published 2 months ago • updated 10 days ago
### Impact Links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or ...
Hugo Markdown titles do not escaped in internal render hooks
GHSA-ppf8-hhpp-f5hj CVE-2024-32875 MODERATE published about 2 years ago • updated 8 days ago
### Impact Title argument in Markdown for links and images not escaped in internal render hooks. Impacted are Hugo users who have these hooks enab...
Hugo does not escape some attributes in internal templates
GHSA-c2xf-9v2r-r2rx CVE-2024-55601 MODERATE published over 1 year ago • updated 8 days ago
## Impact Some HTML attributes in Markdown in the internal templates listed below not escaped. Impacted are Hugo users who do not trust their Mark...
Hugo's Node tool execution allows file system access outside the project directory
GHSA-x597-9fr4-5857 CVE-2026-44301 MODERATE published about 1 month ago • updated 10 days ago
## Impact When building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools wit...
Recent PRs
Package Details
Name: github.com/gohugoio/hugo
Ecosystem: go
PURL Type: golang
Package URL: pkg:golang/github.com/gohugoio/hugo
JSON API: View JSON
Security Advisories

5

Active advisories
HIGH 1
MODERATE 4
View All golang Advisories
Package Information
Description:

Repository: https://github.com/gohugoio/hugo
Homepage: https://github.com/gohugoio/hugo
Latest Release: v0.147.7
about 1 year ago
Dependent Repos: 210
Dependent Packages: 232
Ranking: Top 0.4395% by dependent repos Top 0.3199% by dependent pkgs
PR Status
Open 77 (30.8%)
Merged 31 (12.4%)
Closed 102 (40.8%)
PR Types
Minor 169 (67.6%)
Patch 41 (16.4%)