Cross-site scripting in Etherpad - CVE-2026-55085
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the pad's web origin.
The vulnerability exists due to improper neutralization of input during web page generation in the numbered-list rendering logic in src/static/js/domline.ts when processing a crafted .etherpad file during import. A remote attacker can upload a crafted .etherpad file containing a malicious numbered-list start attribute to execute arbitrary JavaScript in the pad's web origin.
User interaction is required to open the imported pad or its time slider.