Cross-site scripting in Etherpad - CVE-2026-55085

 

Cross-site scripting in Etherpad - CVE-2026-55085

Published: September 22, 2026


Vulnerability identifier: #VU151593
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-55085
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript in the pad's web origin.

The vulnerability exists due to improper neutralization of input during web page generation in the numbered-list rendering logic in src/static/js/domline.ts when processing a crafted .etherpad file during import. A remote attacker can upload a crafted .etherpad file containing a malicious numbered-list start attribute to execute arbitrary JavaScript in the pad's web origin.

User interaction is required to open the imported pad or its time slider.


Affected software

Etherpad

How to mitigate CVE-2026-55085

Install security update from vendor's website.

Etherpad - update to 3.3.1

External References

Related Security Bulletins