A high-severity flaw tracked as CVE-2026-75926 allowed arbitrary command execution during Hugo site builds by abusing the static site generator’s Node.js permission model. In affected versions, Hugo added tailwindcss to its default security.exec.allow list and launched it with Node’s --allow-child-process flag; because TailwindCSS loads tailwind.config.js with require, attacker-controlled top-level code in that file could call child_process and spawn commands outside the intended restrictions. A malicious theme, module, or starter template could therefore execute code with the privileges of the user running the build.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
On August 18, 2026, CVE-2026-75926 was published describing arbitrary command execution during Hugo builds via TailwindCSS bypassing the Node.js permission model in versions 0.162.0 through before 0.165.0. The entry states Hugo 0.165.0 fixes the issue by removing tailwindcss from the default security.exec.allow list.
On August 10, 2026, Hugo committed a change removing tailwindcss from the default security.exec.allow list and updating tests so Tailwind execution must be explicitly opted in via configuration.
On August 9, 2026, Hugo maintainers opened issue #15178 proposing removal of TailwindCSS from the default security.exec.allow list because it required a much more permissive setup than Hugo's stricter default security model intended.
In Hugo 0.162.0, tailwindcss was added to the default AllowChildProcess configuration, causing Hugo to launch it with Node's --allow-child-process flag. This created the condition later described as CVE-2026-75926.
Hugo introduced the Node.js permission model in version 0.161.0 to harden execution security for supported JavaScript tooling such as PostCSS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.