PT-2026-69156 · Lakefs+1 · Lakefs+1

CVE-2026-48026

·

Published

2026-08-07

·

Updated

2026-08-12

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions lakeFS versions prior to 1.81.1 lakeFS Enterprise versions prior to 1.84.0
Description The Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write access to any repository branch can commit a .md object containing arbitrary HTML or JavaScript. When another user opens that object or navigates to a repository or directory containing a malicious README.md, the attacker-supplied script executes within the user's authenticated session.
Recommendations Update lakeFS to version 1.81.1 or later. Update lakeFS Enterprise to version 1.84.0 or later. As a temporary mitigation for lakeFS Enterprise, disable Markdown rendering by adding the appropriate YAML to the configuration.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48026
GHSA-C2R5-5J4W-2XFF

Affected Products

Lakefs
Lakefs-Enterprise