{"document":{"aggregate_severity":{"namespace":"https://access.redhat.com/security/updates/classification/","text":"Moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright © Red Hat, Inc. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"legal_disclaimer","text":"This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.","title":"Terms of Use"}],"publisher":{"category":"vendor","contact_details":"https://access.redhat.com/security/team/contact/","issuing_authority":"Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.","name":"Red Hat Product Security","namespace":"https://www.redhat.com"},"references":[{"category":"self","summary":"Canonical URL","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89258.json"}],"title":"hugo: github.com/gohugoio/hugo: Hugo: Information disclosure via symlink confinement bypass","tracking":{"current_release_date":"2026-09-22T13:12:20+00:00","generator":{"date":"2026-09-22T13:12:20+00:00","engine":{"name":"Red Hat SDEngine","version":"5.4.0"}},"id":"CVE-2026-89258","initial_release_date":"2026-09-11T11:15:34.357000+00:00","revision_history":[{"date":"2026-09-11T11:15:34.357000+00:00","number":"1","summary":"Initial version"},{"date":"2026-09-22T12:21:46+00:00","number":"2","summary":"Current version"},{"date":"2026-09-22T13:12:20+00:00","number":"3","summary":"Last generated version"}],"status":"final","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"Red Hat Enterprise Linux 10","product":{"name":"Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10","product_identification_helper":{"cpe":"cpe:/o:redhat:enterprise_linux:10"}}}],"category":"product_family","name":"Red Hat Enterprise Linux 10"},{"branches":[{"category":"product_name","name":"Red Hat Hardened Images","product":{"name":"Red Hat Hardened Images","product_id":"red_hat_hardened_images","product_identification_helper":{"cpe":"cpe:/a:redhat:hummingbird:1"}}}],"category":"product_family","name":"Red Hat Hardened Images"},{"branches":[{"category":"product_name","name":"Red Hat OpenShift GitOps","product":{"name":"Red Hat OpenShift GitOps","product_id":"red_hat_openshift_gitops","product_identification_helper":{"cpe":"cpe:/a:redhat:openshift_gitops:1"}}}],"category":"product_family","name":"Red Hat OpenShift GitOps"},{"branches":[{"category":"product_name","name":"Red Hat OpenStack Platform 18.0","product":{"name":"Red Hat OpenStack Platform 18.0","product_id":"red_hat_openstack_platform_18.0","product_identification_helper":{"cpe":"cpe:/a:redhat:openstack:18.0"}}}],"category":"product_family","name":"Red Hat OpenStack Platform 18.0"},{"category":"product_version","name":"grafana","product":{"name":"grafana","product_id":"grafana","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana"}}},{"category":"product_version","name":"grafana.src","product":{"name":"grafana.src","product_id":"grafana.src","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana?arch=src"}}},{"category":"product_version","name":"grafana-selinux","product":{"name":"grafana-selinux","product_id":"grafana-selinux","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana-selinux"}}},{"category":"product_version","name":"grafana12.4.src","product":{"name":"grafana12.4.src","product_id":"grafana12.4.src","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana12.4@12.4.10-0.6.hum1?arch=src"}}},{"category":"product_version","name":"grafana13.1.src","product":{"name":"grafana13.1.src","product_id":"grafana13.1.src","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana13.1@13.1.6-0.2.hum1?arch=src"}}},{"category":"product_version","name":"grafana13.2.src","product":{"name":"grafana13.2.src","product_id":"grafana13.2.src","product_identification_helper":{"purl":"pkg:rpm/redhat/grafana13.2@13.2.1-0.5.hum1?arch=src"}}},{"category":"product_version","name":"hugo.src","product":{"name":"hugo.src","product_id":"hugo.src","product_identification_helper":{"purl":"pkg:rpm/redhat/hugo@0.166.0-0.1.hum1?arch=src"}}},{"category":"product_version","name":"openshift-gitops-1/argocd-rhel8","product":{"name":"openshift-gitops-1/argocd-rhel8","product_id":"openshift-gitops-1/argocd-rhel8","product_identification_helper":{"purl":"pkg:oci/argocd-rhel8@sha256:b02520ce147855c753bc0d8a8c329313f59e0a52dba8c3816f9b215236a7fd8c?repository_url=registry.redhat.io/openshift-gitops-1/argocd-rhel8"}}},{"category":"product_version","name":"openshift-gitops-1/argocd-rhel9","product":{"name":"openshift-gitops-1/argocd-rhel9","product_id":"openshift-gitops-1/argocd-rhel9","product_identification_helper":{"purl":"pkg:oci/argocd-rhel9@sha256:569c756cd88e5e6bc460b98694f2103d65fe7d8219abf0cba3f1c8d2abc9476b?repository_url=registry.redhat.io/openshift-gitops-1/argocd-rhel9"}}},{"category":"product_version","name":"rhoso-operators/openstack-operator-bundle","product":{"name":"rhoso-operators/openstack-operator-bundle","product_id":"rhoso-operators/openstack-operator-bundle","product_identification_helper":{"purl":"pkg:oci/openstack-operator-bundle@sha256:7f5ff837fb30c5f21fc329bcecda625da9a476d6e6cc3bae462c9fed311d53e2?repository_url=registry.redhat.io/rhoso-operators/openstack-operator-bundle"}}}],"category":"vendor","name":"Red Hat"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"grafana as a component of Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10:grafana"},"product_reference":"grafana","relates_to_product_reference":"red_hat_enterprise_linux_10"},{"category":"default_component_of","full_product_name":{"name":"grafana-selinux as a component of Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10:grafana-selinux"},"product_reference":"grafana-selinux","relates_to_product_reference":"red_hat_enterprise_linux_10"},{"category":"default_component_of","full_product_name":{"name":"grafana.src as a component of Red Hat Enterprise Linux 10","product_id":"red_hat_enterprise_linux_10:grafana.src"},"product_reference":"grafana.src","relates_to_product_reference":"red_hat_enterprise_linux_10"},{"category":"default_component_of","full_product_name":{"name":"grafana12.4.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:grafana12.4.src"},"product_reference":"grafana12.4.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"grafana13.1.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:grafana13.1.src"},"product_reference":"grafana13.1.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"grafana13.2.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:grafana13.2.src"},"product_reference":"grafana13.2.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"hugo.src as a component of Red Hat Hardened Images","product_id":"red_hat_hardened_images:hugo.src"},"product_reference":"hugo.src","relates_to_product_reference":"red_hat_hardened_images"},{"category":"default_component_of","full_product_name":{"name":"openshift-gitops-1/argocd-rhel8 as a component of Red Hat OpenShift GitOps","product_id":"red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel8"},"product_reference":"openshift-gitops-1/argocd-rhel8","relates_to_product_reference":"red_hat_openshift_gitops"},{"category":"default_component_of","full_product_name":{"name":"openshift-gitops-1/argocd-rhel9 as a component of Red Hat OpenShift GitOps","product_id":"red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel9"},"product_reference":"openshift-gitops-1/argocd-rhel9","relates_to_product_reference":"red_hat_openshift_gitops"},{"category":"default_component_of","full_product_name":{"name":"rhoso-operators/openstack-operator-bundle as a component of Red Hat OpenStack Platform 18.0","product_id":"red_hat_openstack_platform_18.0:rhoso-operators/openstack-operator-bundle"},"product_reference":"rhoso-operators/openstack-operator-bundle","relates_to_product_reference":"red_hat_openstack_platform_18.0"}]},"vulnerabilities":[{"cve":"CVE-2026-89258","cwe":{"id":"CWE-59","name":"Improper Link Resolution Before File Access ('Link Following')"},"discovery_date":"2026-09-11T11:33:08.749972+00:00","flags":[{"label":"component_not_present","product_ids":["red_hat_hardened_images:grafana12.4.src","red_hat_hardened_images:grafana13.1.src","red_hat_hardened_images:grafana13.2.src"]},{"label":"vulnerable_code_not_present","product_ids":["red_hat_hardened_images:hugo.src"]}],"ids":[{"system_name":"Red Hat Bugzilla ID","text":"2531847"}],"notes":[{"category":"description","text":"A flaw was found in Hugo, a static site generator. This vulnerability allows an attacker, who can place a symbolic link (symlink) in a mounted directory, to bypass path confinement. This bypass enables functions performing direct resource lookups to follow the symlink and read files outside the intended project boundaries. The consequence is the disclosure of sensitive file contents within the generated site.","title":"Vulnerability description"},{"category":"summary","text":"hugo: github.com/gohugoio/hugo: Hugo: Information disclosure via symlink confinement bypass","title":"Vulnerability summary"},{"category":"other","text":"This Moderate impact information disclosure flaw in Hugo, a static site generator, arises from improper handling of symlinks in locally vendored themes. Exploitation requires an attacker to either place a malicious symlink within a mounted directory or convince a site author to do so, leading to the disclosure of files outside the intended project boundaries during site generation. The vulnerability is not exploitable when themes are managed as Go modules.","title":"Statement"},{"category":"general","text":"The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.","title":"CVSS score applicability"}],"product_status":{"known_affected":["red_hat_enterprise_linux_10:grafana","red_hat_enterprise_linux_10:grafana-selinux","red_hat_enterprise_linux_10:grafana.src","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel8","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel9","red_hat_openstack_platform_18.0:rhoso-operators/openstack-operator-bundle"],"known_not_affected":["red_hat_hardened_images:grafana12.4.src","red_hat_hardened_images:grafana13.1.src","red_hat_hardened_images:grafana13.2.src","red_hat_hardened_images:hugo.src"]},"references":[{"category":"self","summary":"Canonical URL","url":"https://access.redhat.com/security/cve/CVE-2026-89258"},{"category":"external","summary":"RHBZ#2531847","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531847"},{"category":"external","summary":"https://www.cve.org/CVERecord?id=CVE-2026-89258","url":"https://www.cve.org/CVERecord?id=CVE-2026-89258"},{"category":"external","summary":"https://nvd.nist.gov/vuln/detail/CVE-2026-89258","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89258"},{"category":"external","summary":"https://github.com/gohugoio/hugo/security/advisories/GHSA-vrv5-r5rf-6v4j","url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-vrv5-r5rf-6v4j"},{"category":"external","summary":"https://www.vulncheck.com/advisories/hugo-before-0.165.0-symlink-confinement-bypass-via-resources-get","url":"https://www.vulncheck.com/advisories/hugo-before-0.165.0-symlink-confinement-bypass-via-resources-get"}],"release_date":"2026-09-11T11:15:34.357000+00:00","remediations":[{"category":"workaround","details":"To mitigate this issue, avoid using locally vendored themes from untrusted sources. Ensure that the Hugo site generation environment is secured and isolated, and that only trusted theme content is processed. If local themes are necessary, verify their integrity and ensure they do not contain malicious symlinks before building the site.","product_ids":["red_hat_enterprise_linux_10:grafana","red_hat_enterprise_linux_10:grafana-selinux","red_hat_enterprise_linux_10:grafana.src","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel8","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel9","red_hat_openstack_platform_18.0:rhoso-operators/openstack-operator-bundle"]},{"category":"none_available","details":"Fix deferred","product_ids":["red_hat_enterprise_linux_10:grafana","red_hat_enterprise_linux_10:grafana-selinux","red_hat_enterprise_linux_10:grafana.src","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel8","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel9","red_hat_openstack_platform_18.0:rhoso-operators/openstack-operator-bundle"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","version":"3.1"},"products":["red_hat_enterprise_linux_10:grafana","red_hat_enterprise_linux_10:grafana-selinux","red_hat_enterprise_linux_10:grafana.src","red_hat_hardened_images:grafana12.4.src","red_hat_hardened_images:grafana13.1.src","red_hat_hardened_images:grafana13.2.src","red_hat_hardened_images:hugo.src","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel8","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel9","red_hat_openstack_platform_18.0:rhoso-operators/openstack-operator-bundle"]}],"threats":[{"category":"impact","details":"Moderate","product_ids":["red_hat_enterprise_linux_10:grafana","red_hat_enterprise_linux_10:grafana-selinux","red_hat_enterprise_linux_10:grafana.src","red_hat_hardened_images:grafana12.4.src","red_hat_hardened_images:grafana13.1.src","red_hat_hardened_images:grafana13.2.src","red_hat_hardened_images:hugo.src","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel8","red_hat_openshift_gitops:openshift-gitops-1/argocd-rhel9","red_hat_openstack_platform_18.0:rhoso-operators/openstack-operator-bundle"]}],"title":"hugo: github.com/gohugoio/hugo: Hugo: Information disclosure via symlink confinement bypass"}]}