Cross-site scripting in Etherpad - #VU151606
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a consumer's origin.
The vulnerability exists due to improper neutralization of input during web page generation in the author colors branch of getHTMLFromAtext when exporting diff HTML. A remote attacker can import a crafted .etherpad file to inject arbitrary HTML or script into the exported diff HTML.
User interaction is required because a consumer must render the exported diff HTML.