Path traversal in Etherpad - #VU151601
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to access filesystem paths outside intended plugin directories.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in plugin dependency path construction when processing plugin dependency names from package.json. A remote privileged user can supply a crafted plugin dependency name to access filesystem paths outside intended plugin directories.
Exploitation requires access to the admin-gated plugin installation feature.