PT-2026-76895 · Etherpad · Etherpad
CVE-2026-55090
·
Published
2026-08-17
·
Updated
2026-08-19
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Etherpad versions prior to 3.3.0
Description
Stored cross-site scripting occurs when the
getHTMLFromAtext() function in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without proper HTML attribute escaping. An attacker can inject controlled values into the attribute pool using moveOpsToNewPool and AttributePool.putAttrib. When a bundled plugin that registers this hook, such as ep font color or ep font size, is used, opening the resulting HTML export executes the malicious value in the Etherpad origin.Recommendations
Update to version 3.3.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etherpad