SB2026092237 - Cross-site scripting in Etherpad
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: CVE-2026-55085)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the pad's web origin.
The vulnerability exists due to improper neutralization of input during web page generation in the numbered-list rendering logic in src/static/js/domline.ts when processing a crafted .etherpad file during import. A remote attacker can upload a crafted .etherpad file containing a malicious numbered-list start attribute to execute arbitrary JavaScript in the pad's web origin.
User interaction is required to open the imported pad or its time slider.
Remediation
Install update from vendor's website.