SB2026092238 - Multiple vulnerabilities in Etherpad



SB2026092238 - Multiple vulnerabilities in Etherpad

Published: September 22, 2026

Security Bulletin ID SB2026092238
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 38% Low 63%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Use of insufficiently random values (CVE-ID: N/A)

CWE-ID: CWE-330 - Use of Insufficiently Random Values

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to predict author, session, or readonly identifiers.

The vulnerability exists due to use of insufficiently random values in author, session, and readonly ID generation when generating token identifiers. A remote attacker can exploit predictable Math.random() output to predict token identifiers.


2) Information Exposure Through Timing Discrepancy (CVE-ID: N/A)

CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to conduct timing attacks against login credentials.

The vulnerability exists due to an observable timing discrepancy in the OIDC interaction login password comparison when processing login attempts. A remote attacker can measure password comparison timing to conduct timing attacks against login credentials.


3) Improper Restriction of Excessive Authentication Attempts (CVE-ID: N/A)

CWE-ID: CWE-307 - Improper Restriction of Excessive Authentication Attempts

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to conduct password-guessing attacks.

The vulnerability exists due to improper restriction of excessive authentication attempts in the OIDC interaction login when processing failed login attempts. A remote attacker can submit repeated failed login attempts to conduct password-guessing attacks.


4) Path traversal (CVE-ID: N/A)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access filesystem paths outside intended plugin directories.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in plugin dependency path construction when processing plugin dependency names from package.json. A remote privileged user can supply a crafted plugin dependency name to access filesystem paths outside intended plugin directories.

Exploitation requires access to the admin-gated plugin installation feature.


5) Improper Handling of Extra Parameters (CVE-ID: N/A)

CWE-ID: CWE-235 - Improper Handling of Extra Parameters

CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject unintended API parameters.

The vulnerability exists due to improper handling of extra parameters in /api/2 request-header processing when merging request headers into the API field set. A remote attacker can submit request headers as unintended API fields to inject unintended API parameters.


6) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to create arbitrary pads.

The vulnerability exists due to improper input validation in API.appendChatMessage when appending chat messages to a specified pad. A remote attacker can invoke API.appendChatMessage for a nonexistent pad to create arbitrary pads.


7) Information Exposure Through an Error Message (CVE-ID: N/A)

CWE-ID: CWE-209 - Information Exposure Through an Error Message

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose filesystem error details.

The vulnerability exists due to generation of an error message containing sensitive information in the admin file server when a filesystem operation fails. A remote attacker can trigger a filesystem error to disclose filesystem error details.


8) Cross-site scripting (CVE-ID: CVE-2026-55090)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary JavaScript in a collaborator's browser.

The vulnerability exists due to improper neutralization of input during web page generation in the getHTMLFromAtext function in src/node/utils/ExportHtml.ts when exporting pad content to HTML. A remote user can inject crafted attribute-pool values into a pad to execute arbitrary JavaScript in a collaborator's browser.

User interaction is required for a collaborator to open the HTML export.


Remediation

Install update from vendor's website.