Cross-Site Request Forgery in Lektor Admin API
Lektor versions 3.3.14 and 3.4.0b15 are vulnerable to CSRF in the admin API, allowing unauthenticated attackers to perform state-changing operations via malicious web pages.
CVE search metadata
CVE search record: CVE-2026-104059. Severity: high. CVSS: 8.1. KEV: no. Product: Lektor (3.3.14, 3.4.0b15). Brief: Cross-Site Request Forgery in Lektor Admin API. Brief link: https://feed.craftedsignal.io/briefs/2026-10-lektor-csrf/
Lektor versions 3.3.14 and 3.4.0b15 contain a critical cross-site request forgery (CSRF) vulnerability within the admin API blueprint. The application fails to implement essential security controls, including CSRF tokens, Origin and Referer validation, CORS configuration, and Host allowlisting. This oversight allows unauthenticated attackers to trick authenticated administrative users into triggering unintended, state-changing actions by luring them to a malicious web page. Successful exploitation enables an attacker to perform arbitrary file writes, delete records, clear build outputs, and initiate deployment publication. Furthermore, through DNS rebinding techniques, an attacker may bypass browser-based protections to access sensitive read endpoints, resulting in unauthorized data disclosure. This vulnerability poses a high risk to the integrity and availability of Lektor-based projects.
Impact
Successful exploitation of CVE-2026-104059 allows unauthenticated remote attackers to compromise the administrative functions of Lektor instances. Impact includes loss of data confidentiality through unauthorized read access, and loss of integrity and availability through arbitrary file writes, deletion of records, and destruction of build environments.
Recommendation
Prioritized actions for security teams:
- Identify and inventory all internet-facing instances of Lektor.
- Implement strict network-level access control lists (ACLs) or authentication proxies (e.g., OAuth2-proxy) in front of the Lektor admin panel as a compensatory control until patches are applied.
- Monitor web server logs for suspicious requests to admin endpoints (/admin/api/newattachment, /admin/api/deleterecord, /admin/api/build, /admin/api/clean, /admin/api/publish) that lack a valid Referer or Origin header, or originate from untrusted cross-origin sources.
Immediate actions
Inventory all Lektor instances and verify version
Mitigations
Implement strict IP-based access controls for admin endpoints
CVE-2026-104059
Detection coverage 1
Detect Suspicious Lektor Admin API Access Without Referer
highDetects potentially malicious cross-origin requests to sensitive Lektor admin API endpoints that lack a Referer header, a common indicator of CSRF attempts.
Detection queries are available on the platform. Get full rules →