Cross-Site Scripting Vulnerability in Etherpad Collaborative Editor
CVE-2026-55087
6.1MEDIUM
What is CVE-2026-55087?
Etherpad, a real-time collaborative editor, is susceptible to cross-site scripting due to improper handling of the 'x-proxy-path' request header from versions 2.1.0 to 3.1.0. The vulnerability allows attackers to inject harmful scripts into HTML, JavaScript, and CSS contents served to administrators by leveraging a shared proxy or Content Delivery Network (CDN) that caches responses. Additionally, version 3.0.0 permits a protocol-relative 'x-proxy-path' value, enabling redirection to attacker-controlled domains. These security risks are applicable when deployments permit unvalidated client-supplied 'x-proxy-path' headers. The issue has been addressed in Etherpad version 3.1.0.
Affected Version(s)
etherpad >= 2.1.0, < 3.1.0
