CVE-2026-48026: lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML

Published Aug 7, 2026
·
Updated

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write access to any repository branch can commit a .md object containing arbitrary HTML/JavaScript. Any other user who opens that object, or who navigates to a repository or directory containing a malicious README.md, executes the attacker-supplied script in their own authenticated session. lakeFS fixes the issue in v1.81.1 and lakeFS Enterprise fixes the issue in in v1.84.0. Enterprise customers using older versions can temporarily disable Markdown rendering by adding YAML to their config. No workaround exists for OSS release. Users are advised to upgrade to the latest version for both lakeFS and lakeFS-Enterprise.

Affected Software

2 affected components
lakeFS lakeFS (open source edition)<1.81.1
lakeFS lakeFS Enterprise<1.84.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade lakeFS Web UI to a version that resolves this vulnerability.

    Fixed in 1.81.1
  2. Upgrade

    Upgrade lakeFS-Enterprise to a version that resolves this vulnerability.

    Fixed in 1.84.0
  3. Configuration

    For enterprise customers on older versions, temporarily disable Markdown rendering by adding the provided YAML to the lakeFS configuration (Markdown rendering must be disabled to mitigate the stored XSS in rendered markdown previews).

    lakeFS Enterprise Markdown rendering = temporarily disable by adding YAML to config

Event History

Aug 7, 2026
CVE Published
via MITRE·10:29 PM
Data Sourced
via MITRE·10:29 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-48026?

The severity of CVE-2026-48026 is high, with a score of 8.7.

2

How do I fix CVE-2026-48026?

To fix CVE-2026-48026, upgrade to lakeFS version 1.81.1 for the open source edition or 1.84.0 for the enterprise edition.

3

What type of vulnerability is CVE-2026-48026?

CVE-2026-48026 is a stored Cross-Site Scripting (XSS) vulnerability.

4

How does CVE-2026-48026 affect lakeFS users?

CVE-2026-48026 can allow malicious users to execute scripts in the context of other users via untrusted markdown previews.

5

Can CVE-2026-48026 affect all lakeFS deployments?

CVE-2026-48026 affects all lakeFS deployments prior to the specified versions, whether open source or enterprise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203