PT-2026-78642 · Etherpad · Etherpad
CVE-2026-55085
·
Published
2026-08-19
·
Updated
2026-08-21
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Etherpad versions prior to 3.3.1
Description
An issue exists where the
result.appendSpan function in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the markup to node.innerHTML. Additionally, the ImportEtherpad.setPadRaw function in src/node/utils/ImportEtherpad.ts accepts attacker-controlled attribute-pool values from a crafted .etherpad import, such as list:number1 and a malicious start value. This allows a user with write access to a pad to store markup that executes cross-site scripting (XSS) when another user or an administrator opens the pad or the /timeslider endpoint.Recommendations
Update to version 3.3.1.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etherpad