PT-2026-76895 · Etherpad · Etherpad

CVE-2026-55090

·

Published

2026-08-17

·

Updated

2026-08-19

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Etherpad versions prior to 3.3.0
Description Stored cross-site scripting occurs when the getHTMLFromAtext() function in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without proper HTML attribute escaping. An attacker can inject controlled values into the attribute pool using moveOpsToNewPool and AttributePool.putAttrib. When a bundled plugin that registers this hook, such as ep font color or ep font size, is used, opening the resulting HTML export executes the malicious value in the Etherpad origin.
Recommendations Update to version 3.3.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55090
GHSA-2JP7-WWPG-3P9W

Affected Products

Etherpad