Use of insufficiently random values in Etherpad - #VU151598
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to predict author, session, or readonly identifiers.
The vulnerability exists due to use of insufficiently random values in author, session, and readonly ID generation when generating token identifiers. A remote attacker can exploit predictable Math.random() output to predict token identifiers.