CVE-2026-104059
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| lektor | lektor | 0 <= 3.3.14 | affected |
| lektor | lektor | 3.4.0b1 <= 3.4.0b15 | affected |
Weaknesses
- CWE-352: Cross-Site Request Forgery (CSRF)
References
- https://gist.github.com/mansurmavlankulov/c7683e3204e84892e442b0196585d5bb
- https://www.vulncheck.com/advisories/lektor-csrf-via-admin-api-endpoints
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.