๐Ÿ” CVE Alert

CVE-2026-75926

HIGH 8.6

Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in common/hexec/exec.go append --allow-child-process whenever the tool being launched is named tailwindcss. TailwindCSS loads the site's tailwind.config.js through require at startup, so top-level code in that file executes inside the permitted Node process and can call child_process to spawn a shell. The spawned process is not a Node process and inherits none of the permission flags, so it runs with the full privileges of the account performing the build. Building a site whose theme, module, or starter template supplies the Tailwind configuration therefore yields arbitrary command execution rather than the confined file access the permission model was introduced to enforce. Hugo 0.165.0 removes tailwindcss from the default security.exec.allow list, so the tool is no longer launched under the default configuration.

CWE CWE-1188
Vendor gohugoio
Product hugo
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for gohugoio hugo

Be the first to know when new high vulnerabilities affecting gohugoio hugo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

gohugoio / hugo
0.162.0 < 0.165.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gohugoio/hugo/commit/8a55df7af2e6da31297245cc54fa2e3b521d93e8 github.com: https://github.com/gohugoio/hugo/issues/15178 github.com: https://github.com/gohugoio/hugo/blob/v0.164.0/config/security/securityConfig.go#L72-L79 github.com: https://github.com/gohugoio/hugo/blob/v0.164.0/common/hexec/exec.go#L292-L295 github.com: https://github.com/gohugoio/hugo vulncheck.com: https://www.vulncheck.com/advisories/hugo-to-x-node-permission-model-bypass-via-default-tailwindcss-child-process-grant

Credits

๐Ÿ” Michael Holmquist