PT-2026-78642 · Etherpad · Etherpad

CVE-2026-55085

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Etherpad versions prior to 3.3.1
Description An issue exists where the result.appendSpan function in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the markup to node.innerHTML. Additionally, the ImportEtherpad.setPadRaw function in src/node/utils/ImportEtherpad.ts accepts attacker-controlled attribute-pool values from a crafted .etherpad import, such as list:number1 and a malicious start value. This allows a user with write access to a pad to store markup that executes cross-site scripting (XSS) when another user or an administrator opens the pad or the /timeslider endpoint.
Recommendations Update to version 3.3.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55085
GHSA-F7H5-V9HM-548J

Affected Products

Etherpad