Closed GoVulnBot closed 4 months ago
Change https://go.dev/cl/586484 mentions this issue: data/reports: add 73 unreviewed reports
Change https://go.dev/cl/590039 mentions this issue: data/reports: add 51 reports
Change https://go.dev/cl/598592 mentions this issue: data/excluded,data/reports: review 2 reports, add GO-2024-2983
CVE-2024-32875 references github.com/gohugoio/hugo, which may be a Go module.
Description: Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are impacted are those who have these hooks enabled and do not trust their Markdown content files. The issue is patched in v0.125.3. As a workaround, replace the templates with user defined templates or disable the internal templates.
References:
Cross references:
See doc/triage.md for instructions on how to triage this report.