PT-2026-69156 · Lakefs+1 · Lakefs+1
CVE-2026-48026
·
Published
2026-08-07
·
Updated
2026-08-12
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
lakeFS versions prior to 1.81.1
lakeFS Enterprise versions prior to 1.84.0
Description
The Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write access to any repository branch can commit a
.md object containing arbitrary HTML or JavaScript. When another user opens that object or navigates to a repository or directory containing a malicious README.md, the attacker-supplied script executes within the user's authenticated session.Recommendations
Update lakeFS to version 1.81.1 or later.
Update lakeFS Enterprise to version 1.84.0 or later.
As a temporary mitigation for lakeFS Enterprise, disable Markdown rendering by adding the appropriate YAML to the configuration.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lakefs
Lakefs-Enterprise