No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 02 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lektor
Lektor lektor |
|
| Vendors & Products |
Lektor
Lektor lektor |
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data. | |
| Title | Lektor 3.3.14 CSRF via Admin API Endpoints | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T15:54:30.895Z
Reserved: 2026-10-01T18:02:50.081Z
Link: CVE-2026-104059
Updated: 2026-10-02T15:54:28.124Z
Status : Deferred
Published: 2026-10-01T19:17:19.480
Modified: 2026-10-02T18:47:49.947
Link: CVE-2026-104059
No data.
OpenCVE Enrichment
Updated: 2026-10-01T19:33:10Z