Cross-Site Request Forgery Vulnerability in Lektor by Lektor Team
CVE-2026-104059
7HIGH
What is CVE-2026-104059?
Versions 3.3.14 and 3.4.0b15 of Lektor contain a cross-site request forgery vulnerability within the admin API blueprint. This security flaw allows unauthenticated attackers to execute state-changing operations by sending cross-origin requests without necessary CSRF tokens, validation of Origin/Referer headers, adequate CORS configuration, or Host allowlisting. The endpoints vulnerable to exploitation include newattachment, deleterecord, build, clean, and publish. Attackers leveraging this vulnerability can potentially write arbitrary files, remove pages, clear build outputs, trigger deployments and publication processes, and even disclose sensitive data through DNS rebinding techniques.
Affected Version(s)
lektor 0 <= 3.3.14
lektor 3.4.0b1 <= 3.4.0b15
