What is CVE-2026-48026?
lakeFS Web UI renders Markdown files from repository objects without sanitizing the resulting HTML, allowing users with write access to perform XSS attacks. Versions prior to 1.81.1 (open source) and 1.84.0 (enterprise) are affected, users must upgrade to the specified versions.
Azərbaycanca: lakeFS-in veb interfeysi repo obyektlərindən Markdown fayllarını HTML-ə çevirərkən sanitizasiya etmir, bu da yazma icazəsi olan istifadəçilərə XSS hücumu təşkil etməyə imkan verir. Açıq mənbə versiyası 1.81.1-dən və Enterprise 1.84.0-dən əvvəlki versiyalar təsirlənir, istifadəçilər göstərilən versiyalara yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which versions of lakeFS are affected by the CVE-2026-48026 XSS vulnerability?
Versions prior to 1.81.1 for open source and 1.84.0 for enterprise are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.