Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Crítico CVE-2026-89259 Multiple Vendors

Vulnerabilidad crítica en Hugo v0.161.0+ permite ejecución de código mediante TailwindCSS

Vulnerabilidad · Publicado 11/09/2026

9.8
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Crítico
Resumen ejecutivo

Hugo, generador de sitios estáticos, ejecuta herramientas Node con permisos insuficientemente restringidos desde la versión 0.161.0. TailwindCSS, incluido en la lista de seguridad por defecto, requiere configuraciones altamente permisivas (--allow-addons, --allow-child-process, --allow-worker) que permiten eludir controles de seguridad previos. Esto afecta a empresas en LATAM que alojan sitios web con Hugo y utilizan TailwindCSS para compilación de estilos.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. Affected versions are those after v0.43; the issue was fixed in v0.165.0 by removing tailwindcss from the default security.exec.allow list. Users who do not use TailwindCSS, or who only build trusted sites, are not affected. As a workaround, users can define a restrictive security.exec.allow list in hugo.toml.

Puntuación CVSS

Score: 9.8/10 — Severidad: CRITICAL — Estado NIST: Received

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Debilidades (CWE)

CWE-250

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Inventariar instancias Hugo ≥v0.161.0 en producción
  • Evaluar si TailwindCSS está habilitado y sus permisos en security.exec.allow
  • Aplicar parcheando Hugo a versión corregida cuando esté disponible o deshabilitar TailwindCSS si no es crítico
  • Auditar procesos Node en ejecución para detectar comportamiento anómalo
  • Consultar NIST NVD para actualizaciones del parche oficial
Esta alerta fue generada automáticamente a partir del NVD del NIST.