OSV 1.4.0 · github-reviewed · 修改于 2021-05-22 02:15
发布时间
2021-06-24 01:28
GitHub 审查时间
2021-05-22 02:15
NVD 发布时间
2020-12-22 07:15
源文件
advisories/github-reviewed/2021/06/GHSA-8j34-9876-pvfq/GHSA-8j34-9876-pvfq.json
Hugo depends on Go's os/exec for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system %PATH% on Windows. However, if a malicious file with the same name (exe or bat) is found in the current working directory at the time of running hugo, the malicious command will be invoked instead of the system one.
Windows users who run hugo inside untrusted Hugo sites are affected.
Users should upgrade to Hugo v0.79.1.