7.7
CVSS V3
Hugo can execute a binary from the current directory on Windows
Hugo depends on Go's os/exec
for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system %PATH%
on Windows. However, if a malicious file with the same name (exe
or bat
) is found in the current working directory at the time of running hugo
, the malicious command will be invoked instead of the system one.
Windows users who run hugo
inside untrusted Hugo sites are affected.
Users should upgrade to Hugo v0.79.1.