github gohugoio/hugo v0.125.3

latest releases: v0.138.0, v0.137.1, v0.137.0...
6 months ago

This release fixes a security issue reported by @ejona86 (see #12411) that could allow XSS injection from Markdown content files if one of the internal link or image render hook templates added in Hugo 0.123.0 are enabled. You typically control and trust the content files, but according to Hugo's security model, we state that "template and configuration authors (you) are trusted, but the data you send in is not."

Don't miss a new hugo release

NewReleases is sending notifications on new releases.