Path Traversal Vulnerability in lakeFS Open-Source Tool by Treeverse
CVE-2026-26187
What is CVE-2026-26187?
The lakeFS tool, developed by Treeverse, presents a path traversal vulnerability that impacts its functionality. Authenticated users could exploit this issue to access files beyond their specified storage bounds. In versions before 1.77.0, the local block adapter failed to enforce sufficient path validation, only checking for prefixes without ensuring a separation. This flaw permits access to sibling directories with similar naming, leading to unauthorized file exposure. Moreover, the system's path verification inadequately restricted object identifiers to their respective storage namespaces, allowing attackers to manipulate path traversal sequences to gain access to files elsewhere. This vulnerability was addressed and resolved in version 1.77.0.
Affected Version(s)
lakeFS < 1.77.0
