CVE-2026-48026
Last modified
CVE-2026-48026 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML.
Description
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write access to any repository branch can commit a `.md` object containing arbitrary HTML/JavaScript. Any other user who opens that object, or who navigates to a repository or directory containing a malicious `README.md`, executes the attacker-supplied script in their own authenticated session. lakeFS fixes the issue in v1.81.1 and lakeFS Enterprise fixes the issue in in v1.84.0. Enterprise customers using older versions can temporarily disable Markdown rendering by adding YAML to their config. No workaround exists for OSS release. Users are advised to upgrade to the latest version for both lakeFS and lakeFS-Enterprise.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| treeverse | lakeFS | < 1.81.1 |
| treeverse | lakeFS-enterprise | < 1.84.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-48026?
How severe is CVE-2026-48026?
How do I fix CVE-2026-48026?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48017DbGate is cross-platform database manager. In versions 7.1.8…8.8
- CVE-2026-4802A flaw was found in Cockpit. This vulnerability allows a rem…8
- CVE-2026-48020Traefik is an HTTP reverse proxy and load balancer. Prior to…10
- CVE-2026-48021In epa4all, prior to version 2026-05-20, an attacker who can…9.1
- CVE-2026-48022@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wrec…6.5
- CVE-2026-48025nebula-mesh is a self-hosted control plane for Slack Nebula …6.9
- CVE-2026-48027Nx Console is the user interface for Nx & Lerna. On 19 May 2…9.8
- CVE-2026-48028Mastodon is a free, open-source social network server based …6.5
- CVE-2026-48029libheif is a HEIF and AVIF file format decoder and encoder. …7.1
- CVE-2026-4803The Royal Elementor Addons plugin for WordPress is vulnerabl…7.2
- CVE-2026-48030Pheditor is a single-file editor and file manager written in…9.9
- CVE-2026-48031go-base is a Go RESTful API Boilerplate template with JWT Au…9.1
Are you affected by CVE-2026-48026?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
