Cross-Site Scripting Vulnerability in Etherpad Collaborative Editor
CVE-2026-55085
What is CVE-2026-55085?
Etherpad, a popular real-time collaborative editor, has a vulnerability related to improper handling of input in its markup rendering. Specifically, prior to version 3.3.1, the application allowed users with write access to inject malicious scripts through crafted .etherpad imports, leading to potential cross-site scripting (XSS) attacks. This occurs when an attacker manipulates the start attribute of a numbered list, affecting the generation of HTML content. When other users open this compromised pad, the malicious JavaScript can execute in their browsers, compromising their session and data. The issue is addressed in the release of version 3.3.1, emphasizing the need for users to update their installations to maintain security.
Affected Version(s)
etherpad < 3.3.1
