3.3.12
9 years ago
6 months ago
Known vulnerabilities in the lektor package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Lektor is an A static content management system. Affected versions of this package are vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'). An attacker can execute arbitrary shell commands by adding a malicious file to the templates directory. This exploit is triggered when a victim's web browser, running on the same machine as the How to fix Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')? Upgrade | [,3.3.11) |