Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site. An attacker who can supply or influence a content file under /content or the output of a content adapter can inject scripts that execute in the browsers of visitors to the affected pages. Only pages whose source file or content-adapter output declares the text/org media type are affected, and sites that fully trust all content sources are not impacted. Version v0.166.0 fixes the issue by introducing a security.allowContent allowlist that denies text/org by default; sites that intentionally author Org Mode content can opt back in with [security] allowContent = ['.*']. Join the discussion | CVE Database V5 | 09/26/2026, 13:23:52 UTC Added: 09/26/2026, 13:33:33 UTC |
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. Affected versions are those after v0.43; the issue was fixed in v0.165.0 by removing tailwindcss from the default security.exec.allow list. Users who do not use TailwindCSS, or who only build trusted sites, are not affected. As a workaround, users can define a restrictive security.exec.allow list in hugo.toml. Join the discussion | CVE Database V5 | 09/11/2026, 11:15:35 UTC Added: 09/11/2026, 11:32:50 UTC |
0 CVE-2026-10618 is a medium severity cross-site scripting (XSS) vulnerability in the Hugo static site generator. The issue arises because Hugo's default fenced-code-block renderer improperly handles attribute values from code-fence info strings, writing them into HTML without proper escaping. This allows an attacker to inject malicious scripts via crafted attribute values, which execute when a user loads the affected page. The vulnerability affects Hugo versions from 0.93.0 through 0.165.0 under default configuration with code fences enabled. No official patch or fix information is provided in the available data. Join the discussion | CVE Database V5 | 08/24/2026, 10:29:10 UTC Added: 08/24/2026, 11:08:14 UTC |
CVE-2026-10582 is a Server-Side Request Forgery (SSRF) vulnerability in the Hugo static site generator. The security.http.urls allowlist only inspects URL text and does not resolve hostnames or verify the actual IP address connected to, allowing bypass via hostnames resolving to internal or cloud metadata addresses. An attacker able to supply a URL through content fields can cause the build process to fetch internal endpoints and embed the response in the generated site output. Join the discussion | CVE Database V5 | 08/24/2026, 10:29:09 UTC Added: 08/24/2026, 11:08:14 UTC |
0 Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in common/hexec/exec.go append --allow-child-process whenever the tool being launched is named tailwindcss. TailwindCSS loads the site's tailwind.config.js through require at startup, so top-level code in that file executes inside the permitted Node process and can call child_process to spawn a shell. The spawned process is not a Node process and inherits none of the permission flags, so it runs with the full privileges of the account performing the build. Building a site whose theme, module, or starter template supplies the Tailwind configuration therefore yields arbitrary command execution rather than the confined file access the permission model was introduced to enforce. Hugo 0.165.0 removes tailwindcss from the default security.exec.allow list, so the tool is no longer launched under the default configuration. Join the discussion | CVE Database V5 | 08/18/2026, 15:47:49 UTC Added: 08/18/2026, 16:06:11 UTC |
Showing 1 to 5 of 5 results