Cross-Site Request Forgery Vulnerability in Lektor by Lektor Team
CVE-2026-104059

7HIGH

Key Information:

Vendor

Lektor

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-104059?

Versions 3.3.14 and 3.4.0b15 of Lektor contain a cross-site request forgery vulnerability within the admin API blueprint. This security flaw allows unauthenticated attackers to execute state-changing operations by sending cross-origin requests without necessary CSRF tokens, validation of Origin/Referer headers, adequate CORS configuration, or Host allowlisting. The endpoints vulnerable to exploitation include newattachment, deleterecord, build, clean, and publish. Attackers leveraging this vulnerability can potentially write arbitrary files, remove pages, clear build outputs, trigger deployments and publication processes, and even disclose sensitive data through DNS rebinding techniques.

Affected Version(s)

lektor 0 <= 3.3.14

lektor 3.4.0b1 <= 3.4.0b15

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mansur Mavlankulov
.