Cross-site scripting in Etherpad - CVE-2026-55090
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a collaborator's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the getHTMLFromAtext function in src/node/utils/ExportHtml.ts when exporting pad content to HTML. A remote user can inject crafted attribute-pool values into a pad to execute arbitrary JavaScript in a collaborator's browser.
User interaction is required for a collaborator to open the HTML export.