<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:lektor:lektor:3.4.0:beta15:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alektorlektor3.4.0beta15/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:24:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alektorlektor3.4.0beta15/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Site Request Forgery in Lektor Admin API</title><link>https://feed.craftedsignal.io/briefs/2026-10-lektor-csrf/</link><pubDate>Thu, 01 Oct 2026 20:24:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-lektor-csrf/</guid><description>Lektor versions 3.3.14 and 3.4.0b15 are vulnerable to CSRF in the admin API, allowing unauthenticated attackers to perform state-changing operations via malicious web pages.</description><content:encoded><![CDATA[<p>Lektor versions 3.3.14 and 3.4.0b15 contain a critical cross-site request forgery (CSRF) vulnerability within the admin API blueprint. The application fails to implement essential security controls, including CSRF tokens, Origin and Referer validation, CORS configuration, and Host allowlisting. This oversight allows unauthenticated attackers to trick authenticated administrative users into triggering unintended, state-changing actions by luring them to a malicious web page. Successful exploitation enables an attacker to perform arbitrary file writes, delete records, clear build outputs, and initiate deployment publication. Furthermore, through DNS rebinding techniques, an attacker may bypass browser-based protections to access sensitive read endpoints, resulting in unauthorized data disclosure. This vulnerability poses a high risk to the integrity and availability of Lektor-based projects.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-104059 allows unauthenticated remote attackers to compromise the administrative functions of Lektor instances. Impact includes loss of data confidentiality through unauthorized read access, and loss of integrity and availability through arbitrary file writes, deletion of records, and destruction of build environments.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Identify and inventory all internet-facing instances of Lektor.</li>
<li>Implement strict network-level access control lists (ACLs) or authentication proxies (e.g., OAuth2-proxy) in front of the Lektor admin panel as a compensatory control until patches are applied.</li>
<li>Monitor web server logs for suspicious requests to admin endpoints (/admin/api/newattachment, /admin/api/deleterecord, /admin/api/build, /admin/api/clean, /admin/api/publish) that lack a valid Referer or Origin header, or originate from untrusted cross-origin sources.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>web-application-vulnerability</category><category>csrf</category><category>lfi</category></item></channel></rss>