A path traversal vulnerability has been identified in the built-in preview/development web server of Lektor versions prior to 3.3.14 on Windows. An attacker with network access can send crafted HTTP requests containing path traversal sequences to read arbitrary files accessible to the process. This can result in disclosure of sensitive information including system files and deployment configuration files that may contain credentials. The vulnerability is limited to the Windows platform and affects the development/preview server component. A proof-of-concept exploit has been published on GitHub. Users should upgrade to Lektor 3.3.14 or later to mitigate the risk. The vulnerability poses a significant risk particularly in environments where the development server is inadvertently exposed to untrusted networks.