Link following in Etherpad - CVE-2026-55086
Published: September 22, 2026
Vulnerability details
The vulnerability allows a local user to overwrite files writable by the Etherpad process and disclose limited information.
The vulnerability exists due to insecure temporary file handling in the ImportHandler and ExportHandler when handling import and export operations using a shared temporary directory. A local user can pre-create a symbolic link at a predicted temporary file path and trigger an import or export operation to overwrite files writable by the Etherpad process and disclose limited information.
Exploitation requires predicting a temporary filename, such as by observing an earlier temporary filename.