VYPR
High severity7.5NVD Advisory· Published Aug 28, 2026

CVE-2026-75418

CVE-2026-75418

Description

A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can send a crafted HTTP request containing path traversal sequences to read arbitrary files accessible to the process, disclosing sensitive information such as system files and deployment configuration files containing credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Lektor/Lektorreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <3.3.14

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.