Ether Etherpad vulnerabilities
6 known vulnerabilities affecting ether/etherpad.
Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2026-55089P2CRITICALCVSS 9.9v>= 2.1.0, < 3.1.02026-08-19
CVE-2026-55089 [CRITICAL] CWE-863 CVE-2026-55089: Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/AP
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists, while src/node/security/OAuth2Provider.ts issues admin: false for configur
nvd
CVE-2026-55087P3MEDIUMCVSS 6.1PoCv>= 2.1.0, < 3.1.02026-08-19
CVE-2026-55087 [MEDIUM] CWE-79 CVE-2026-55087: Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-con
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admin without sanitization, Vary: x-proxy-path, or Cache-Control: private, no-store. A shared proxy or CDN can cache th
nvd
CVE-2026-55085P3CRITICALCVSS 9.6fixed in 3.3.12026-08-19
CVE-2026-55085 [CRITICAL] CWE-79 CVE-2026-55085: Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/dom
Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated markup to node.innerHTML. ImportEtherpad.setPadRaw in src/node/utils/ImportEtherpad.ts accepts attacker-controlled
nvd
CVE-2026-55088P3MEDIUMCVSS 6.8v>= 2.6.0, < 3.1.02026-08-19
CVE-2026-55088 [MEDIUM] CWE-200 CVE-2026-55088: Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/expr
Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTransfer/{uuid}. Although the record includes createdAt, the transfer has no expiration check, is not removed after s
nvd
CVE-2026-55090P4MEDIUMCVSS 5.3fixed in 3.3.02026-08-19
CVE-2026-55090 [MEDIUM] CWE-79 CVE-2026-55090: Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/Exp
Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute escaping. A pad editor can place an attacker-controlled value into the attribute pool through moveOpsToNewPool and Att
nvd
CVE-2026-55086P4MEDIUMCVSS 4.2fixed in 3.1.02026-08-19
CVE-2026-55086 [MEDIUM] CWE-59 CVE-2026-55086: Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and
Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared world-writable temporary directory, a local unprivileged attacker who predicts a filename can precreate a symbolic lin
nvd