{"id":"CVE-2026-104059","summary":"Lektor 3.3.14 CSRF via Admin API Endpoints","details":"Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.","modified":"2026-10-02T03:47:26.059395287Z","published":"2026-10-01T18:17:39.168Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-352"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104059.json"},"references":[{"type":"ARTICLE","url":"https://gist.github.com/mansurmavlankulov/c7683e3204e84892e442b0196585d5bb"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104059.json"},{"type":"PACKAGE","url":"https://github.com/lektor/lektor"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104059"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/lektor-csrf-via-admin-api-endpoints"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lektor/lektor","events":[{"introduced":"0"},{"last_affected":"1e4c15029afd5c862557cfe2c1bc564733be04ad"},{"introduced":"6d7bd4db43584ffa14158ccf5f4f5211a2567f14"},{"last_affected":"85a9ed91f534492d0f9eadb919c3bae9d917564b"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"3.3.14"},{"introduced":"3.4.0b1"},{"last_affected":"3.4.0b15"}]}}],"versions":["v3.4.0b15","v3.3.14","v3.4.0b14","v3.3.13","v3.4.0b13","v3.3.12","v3.3.11","v3.4.0b12","v3.4.0b11","v3.4.0b10","v3.3.10","v3.4.0b9","v3.4.0b8","v3.4.0b7","v3.4.0b6","v3.3.9","v3.4.0b5","v3.3.8","v3.4.0b4","v3.3.7","v3.4.0b3","v3.4.0b2","v3.4.0b1","v3.3.6","v3.3.5","v3.3.4","v3.3.3","v3.3.2","v3.3.1","v3.3.0","3.2.0","3.2.dev0","3.1.2","3.1.1","3.1","3.0","2.2","2.1","2.0","1.0","0.96"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104059.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}