Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104059— Lektor 3.3.14 CSRF via Admin API Endpoints

Quick assessment

Affected
lektor lektor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Lektor 3.3.14 和 3.4.0b15 版本的管理 API 蓝图存在跨站请求伪造(CSRF)漏洞。该漏洞允许未经身份验证的攻击者通过发送缺少 CSRF 令牌、Origin/Referer 校验、CORS 配置或 Host 白名单验证的跨域请求,执行状态变更操作。攻击者可利用恶意网页调用 newattachment、deleterecord、build、clean 和 publish 等接口,从而写入任意文件、删除页面、清除构建输出、触发部署发布;此外,通过 DNS 重绑定技术还可访问读取类接口以泄露数据。

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104059

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lektor 3.3.14 CSRF via Admin API Endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
lektor lektor 0 ~ 3.3.14 -

II. Public POCs for CVE-2026-104059

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104059

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-104059 (1)

Proof of Concept for CVE-2026-104059 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104059

No comments yet


Leave a comment