Cross-Site Scripting Vulnerability in Etherpad Collaborative Editor
CVE-2026-55087

6.1MEDIUM

Key Information:

Vendor

Ether

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-55087?

Etherpad, a real-time collaborative editor, is susceptible to cross-site scripting due to improper handling of the 'x-proxy-path' request header from versions 2.1.0 to 3.1.0. The vulnerability allows attackers to inject harmful scripts into HTML, JavaScript, and CSS contents served to administrators by leveraging a shared proxy or Content Delivery Network (CDN) that caches responses. Additionally, version 3.0.0 permits a protocol-relative 'x-proxy-path' value, enabling redirection to attacker-controlled domains. These security risks are applicable when deployments permit unvalidated client-supplied 'x-proxy-path' headers. The issue has been addressed in Etherpad version 3.1.0.

Affected Version(s)

etherpad >= 2.1.0, < 3.1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.