Remote Code Execution Vulnerability in lakeFS Web UI by Treeverse
CVE-2026-48026
8.7HIGH
What is CVE-2026-48026?
The lakeFS Web UI has a vulnerability that allows users with write access to commit malicious markdown files, which can contain arbitrary HTML/JavaScript. This can lead to execution of the attacker's script within the authentic user's session when the markdown content is rendered. It affects versions before 1.81.1 for the open-source edition and before 1.84.0 for the enterprise edition. To mitigate the risk, users should upgrade to the latest version or disable Markdown rendering if using an older enterprise version, but no workaround exists for the open-source version.
Affected Version(s)
lakeFS < 1.81.1
lakeFS-enterprise < 1.84.0
