Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-352"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104059.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.3.14"
},
{
"introduced": "3.4.0b1"
},
{
"last_affected": "3.4.0b15"
}
],
"source": "AFFECTED_FIELD"
}