Cross-Site Scripting Vulnerability in Etherpad Collaborative Editor
CVE-2026-55085

9.6CRITICAL

Key Information:

Vendor

Ether

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-55085?

Etherpad, a popular real-time collaborative editor, has a vulnerability related to improper handling of input in its markup rendering. Specifically, prior to version 3.3.1, the application allowed users with write access to inject malicious scripts through crafted .etherpad imports, leading to potential cross-site scripting (XSS) attacks. This occurs when an attacker manipulates the start attribute of a numbered list, affecting the generation of HTML content. When other users open this compromised pad, the malicious JavaScript can execute in their browsers, compromising their session and data. The issue is addressed in the release of version 3.3.1, emphasizing the need for users to update their installations to maintain security.

Affected Version(s)

etherpad < 3.3.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.