CVE-2026-104059
Lektor 3.3.14 CSRF via Admin API Endpoints
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.
| CWE | CWE-352 |
| Vendor | lektor |
| Product | lektor |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for lektor lektor
Be the first to know when new high vulnerabilities affecting lektor lektor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Affected Versions
lektor / lektor
0 โค 3.3.14 3.4.0b1 โค 3.4.0b15
References
Credits
Mansur Mavlankulov