lektor@2.2 vulnerabilities

A static content management system.

  • latest version

    3.3.12

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    6 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the lektor package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    Lektor is an A static content management system.

    Affected versions of this package are vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'). An attacker can execute arbitrary shell commands by adding a malicious file to the templates directory. This exploit is triggered when a victim's web browser, running on the same machine as the lektor server command, accesses an untrusted website that uses JavaScript to send requests to localhost port 5000.

    How to fix Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')?

    Upgrade Lektor to version 3.3.11 or higher.

    [,3.3.11)