{"id":"GHSA-ppf8-hhpp-f5hj","summary":"Hugo Markdown titles do not escaped in internal render hooks","details":"### Impact\n\nTitle argument in Markdown for links and images not escaped in internal render hooks. Impacted are Hugo users who have these hooks enabled and do not trust their Markdown content files.\n\n### Patches\n\nPatched in v0.125.3.\n\n### Workarounds\n\nReplace with user defined templates or disable the internal templates: https://gohugo.io/getting-started/configuration-markup/#renderhooksimageenabledefault\n\n### References\n\nhttps://github.com/gohugoio/hugo/releases/tag/v0.125.3","aliases":["CVE-2024-32875","GO-2024-2747"],"modified":"2026-07-17T21:08:47.190543210Z","published":"2024-04-23T21:16:15Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-23T21:16:15Z","nvd_published_at":"2024-04-23T21:15:48Z"},"references":[{"type":"WEB","url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-ppf8-hhpp-f5hj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32875"},{"type":"WEB","url":"https://github.com/gohugoio/hugo/commit/15a4b9b33715887001f6eff30721d41c0d4cfdd1"},{"type":"PACKAGE","url":"https://github.com/gohugoio/hugo"},{"type":"WEB","url":"https://github.com/gohugoio/hugo/releases/tag/v0.125.3"},{"type":"WEB","url":"https://gohugo.io/getting-started/configuration-markup/#renderhooksimageenabledefault"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-2747"}],"affected":[{"package":{"name":"github.com/gohugoio/hugo","ecosystem":"Go","purl":"pkg:golang/github.com/gohugoio/hugo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.123.0"},{"fixed":"0.125.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-ppf8-hhpp-f5hj/GHSA-ppf8-hhpp-f5hj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}