-
CVSS Score
-The vulnerability stems from Hugo's internal templates not properly escaping HTML attributes when rendering user-controlled Markdown content. The commit diff shows:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/gohugoio/hugo | go | >= 0.123.0, < 0.139.4 | 0.139.4 |
A Semantic Attack on Google Gemini - Read the Latest Research