Impact
A path traversal flaw exists in the built‑in preview and development web server of Lektor versions earlier than 3.3.14 running on Windows. By sending a specially crafted HTTP request that contains directory traversal sequences, an attacker with network reachability to the server can read any file the server process can access. This can expose sensitive data such as system configuration files and credential files, compromising confidentiality and potentially allowing further exploitation.
Affected Systems
The vulnerability affects any installation of Lektor running its preview server on Windows where the version is less than 3.3.14. The preview/development server is intended for local testing and not designed for exposed network use.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity flaw. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs network connectivity to the preview server to send a crafted HTTP request; no additional authentication or privilege is required. The attack can be automated through scripts that iterate over common file paths to harvest sensitive information.
OpenCVE Enrichment