{"id":"CVE-2026-104059","title":"Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origi…","summary":"Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origi…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","cwe":["CWE-352"],"vendor":"lektor","product":"lektor","affected":["lektor <= 3.3.14","lektor >= 3.4.0b1 <= 3.4.0b15"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T19:17:19.480","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104059","references":[{"url":"https://gist.github.com/mansurmavlankulov/c7683e3204e84892e442b0196585d5bb","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/lektor-csrf-via-admin-api-endpoints","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T18:55:42.391Z","slug":"CVE-2026-104059","body":"## Overview\n\nLektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}