CVE-2026-35166 | gohugoio hugo up to 0.159.1 Link cross site scripting (GHSA-mcv8-8m8x-48pg)
A vulnerability was found in gohugoio hugo up to 0.159.1 and classified as problematic. This affects an unknown part of the component Link Handler. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-35166. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.