CVE-2026-104059: Lektor 3.3.14 CSRF via Admin API Endpoints
Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Lektor versions 3.3.14 and 3.4.0b15 are identified as affected. Exposure requires a victim to access a malicious web page while the Lektor admin API is reachable from the victim's browser.
What does an attacker need to exploit the vulnerability?
No authentication is required by the attacker, but exploitation requires user interaction: a victim must load a malicious cross-origin page. The issue is enabled by the absence of CSRF tokens, Origin/Referer validation, CORS configuration, and Host allowlisting on the affected admin API endpoints.
What actions can be performed through the vulnerable endpoints?
An attacker can target newattachment, deleterecord, build, clean, and publish to write arbitrary files, delete pages, remove build output, or trigger publication. DNS rebinding can also be used to reach read endpoints and disclose data.
How can administrators determine whether they are affected?
Check whether the deployment runs Lektor 3.3.14 or 3.4.0b15 and exposes the admin API to browsers. Review whether the admin API accepts cross-origin state-changing requests without CSRF protections or Origin/Referer validation.