Skip to content

Instantly share code, notes, and snippets.

@alon710
Created February 13, 2026 19:10
Show Gist options
  • Select an option

  • Save alon710/51f5e184eeca1d68fbd1bc99e57875f4 to your computer and use it in GitHub Desktop.

Select an option

Save alon710/51f5e184eeca1d68fbd1bc99e57875f4 to your computer and use it in GitHub Desktop.
CVE-2026-26187: CVE-2026-26187: escaping the Lake with a Path Traversal Two-Step - CVE Security Report

CVE-2026-26187: CVE-2026-26187: escaping the Lake with a Path Traversal Two-Step

CVSS Score: 8.1 Published: 2026-02-13 Full Report: https://cvereports.com/reports/CVE-2026-26187

Summary

A critical path traversal vulnerability in the lakeFS Local Block Adapter allows authenticated users to break out of their storage namespace boundaries. By exploiting a weak prefix validation check and a namespace logic error, attackers can read and write files in sibling repositories or unrelated directories on the host filesystem.

TL;DR

lakeFS failed to properly sanitize file paths in its Local Block Adapter. Due to a missing trailing slash in a prefix check and loose namespace validation, attackers can use ../ sequences to access files outside their repo. Fixed in v1.77.0.

Exploit Status: POC

Technical Details

  • CVE ID: CVE-2026-26187
  • CVSS Score: 8.1 (High)
  • CWE: CWE-22 (Path Traversal)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Affected Versions: < 1.77.0
  • Fix Version: 1.77.0

Affected Systems

  • lakeFS (Local Block Adapter)
  • treeverse/lakeFS: < 1.77.0 (Fixed in: 1.77.0)

Mitigation

  • Strict Prefix Validation with Separators
  • Namespace-level Path Anchoring
  • Input Sanitization via filepath.Clean

Remediation Steps:

  1. Upgrade lakeFS to version 1.77.0 or later immediately.
  2. Audit existing Local Block Adapter configurations for sibling directories that might have been exposed.
  3. If unable to upgrade, restrict access to the lakeFS API to trusted networks only.

References


Generated by CVEReports - Automated Vulnerability Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment