Remote Code Execution Vulnerability in lakeFS Web UI by Treeverse
CVE-2026-48026

8.7HIGH

Key Information:

Vendor

Treeverse

Vendor
CVE Published:
7 August 2026

What is CVE-2026-48026?

The lakeFS Web UI has a vulnerability that allows users with write access to commit malicious markdown files, which can contain arbitrary HTML/JavaScript. This can lead to execution of the attacker's script within the authentic user's session when the markdown content is rendered. It affects versions before 1.81.1 for the open-source edition and before 1.84.0 for the enterprise edition. To mitigate the risk, users should upgrade to the latest version or disable Markdown rendering if using an older enterprise version, but no workaround exists for the open-source version.

Affected Version(s)

lakeFS < 1.81.1

lakeFS-enterprise < 1.84.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.