CVE-2026-75418
nicheUnauthenticated Path Traversal in Lektor Preview Server Exposes Files on Windows
CVE-2026-75418 is a path traversal vulnerability (CWE-22) in the built-in preview/development web server of the Lektor static site generator on Windows, affecting all versions before 3.3.14. An unauthenticated attacker with network access to the server can send a crafted HTTP request containing path traversal sequences, causing the server to read files outside its intended document root. Successful exploitation discloses arbitrary files accessible to the server process, including operating system files and deployment configuration files that may contain credentials. Only Windows deployments of Lektor's preview/development server that are reachable over a network are affected. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS currently assigns a low 0.4% probability of exploitation within 30 days.
What to do: Upgrade Windows installations to Lektor 3.3.14 or later, which resolves this issue. Until patched, avoid exposing the built-in preview/development server to untrusted networks (restrict it to localhost or firewall it), and review files readable by the server process, especially deployment configurations containing credentials, for exposure via traversal requests in server logs.
| Lektor built-in preview/development web server | All versions prior to 3.3.14 (< 3.3.14), on Windows |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can send a crafted HTTP request containing path traversal sequences to read arbitrary files accessible to the process, disclosing sensitive information such as system files and deployment configuration files containing credentials.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.