Cross-site scripting in Etherpad - CVE-2026-55087
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in an administrator's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the admin static-serving handler when processing an x-proxy-path header in admin HTML, JavaScript, and CSS assets. A remote attacker can send a request with a crafted x-proxy-path header to execute arbitrary JavaScript in an administrator's browser.
User interaction is required, and cache poisoning requires a shared cache that does not vary cached responses by the x-proxy-path header.