SB2026092238 - Multiple vulnerabilities in Etherpad
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Use of insufficiently random values (CVE-ID: N/A)
CWE-ID: CWE-330 - Use of Insufficiently Random Values
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to predict author, session, or readonly identifiers.
The vulnerability exists due to use of insufficiently random values in author, session, and readonly ID generation when generating token identifiers. A remote attacker can exploit predictable Math.random() output to predict token identifiers.
2) Information Exposure Through Timing Discrepancy (CVE-ID: N/A)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to conduct timing attacks against login credentials.
The vulnerability exists due to an observable timing discrepancy in the OIDC interaction login password comparison when processing login attempts. A remote attacker can measure password comparison timing to conduct timing attacks against login credentials.
3) Improper Restriction of Excessive Authentication Attempts (CVE-ID: N/A)
CWE-ID: CWE-307 - Improper Restriction of Excessive Authentication Attempts
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to conduct password-guessing attacks.
The vulnerability exists due to improper restriction of excessive authentication attempts in the OIDC interaction login when processing failed login attempts. A remote attacker can submit repeated failed login attempts to conduct password-guessing attacks.
4) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access filesystem paths outside intended plugin directories.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in plugin dependency path construction when processing plugin dependency names from package.json. A remote privileged user can supply a crafted plugin dependency name to access filesystem paths outside intended plugin directories.
Exploitation requires access to the admin-gated plugin installation feature.
5) Improper Handling of Extra Parameters (CVE-ID: N/A)
CWE-ID: CWE-235 - Improper Handling of Extra Parameters
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject unintended API parameters.
The vulnerability exists due to improper handling of extra parameters in /api/2 request-header processing when merging request headers into the API field set. A remote attacker can submit request headers as unintended API fields to inject unintended API parameters.
6) Input validation error (CVE-ID: N/A)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to create arbitrary pads.
The vulnerability exists due to improper input validation in API.appendChatMessage when appending chat messages to a specified pad. A remote attacker can invoke API.appendChatMessage for a nonexistent pad to create arbitrary pads.
7) Information Exposure Through an Error Message (CVE-ID: N/A)
CWE-ID: CWE-209 - Information Exposure Through an Error Message
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose filesystem error details.
The vulnerability exists due to generation of an error message containing sensitive information in the admin file server when a filesystem operation fails. A remote attacker can trigger a filesystem error to disclose filesystem error details.
8) Cross-site scripting (CVE-ID: CVE-2026-55090)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in a collaborator's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the getHTMLFromAtext function in src/node/utils/ExportHtml.ts when exporting pad content to HTML. A remote user can inject crafted attribute-pool values into a pad to execute arbitrary JavaScript in a collaborator's browser.
User interaction is required for a collaborator to open the HTML export.
Remediation
Install update from vendor's website.