Comment by vntok

5 hours ago

Sorry in advance if you were joking, but for readers who aren't in the know: Hugo had, in fact, two 9.3 CVSS vulnerabilities just 11 days ago...

https://app.opencve.io/cve/CVE-2026-89259

https://app.opencve.io/cve/CVE-2026-89258

To be clear, those are CVEs in the tooling, not in the generated static sites. Not great, but very different from this WordPress CVE

I have full control over the inputs for hugo and the output is pure static HTML. It's better if there are no CVEs but I really don't sweat these. My Hugo template runs 100% pure CSS and no JS.