Cross-Site Scripting Vulnerability in Etherpad Real-Time Collaborative Editor
CVE-2026-55090

5.3MEDIUM

Key Information:

Vendor

Ether

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-55090?

A cross-site scripting vulnerability has been identified in Etherpad prior to version 3.3.0. The getHTMLFromAtext function improperly interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without adequate HTML attribute escaping. This allows an attacker to introduce malicious code that could execute when the manipulated HTML is rendered in the Etherpad environment. Notably, when bundled plugins like ep_font_color or ep_font_size are registered, they can facilitate the injection of attacker-controlled values, making it possible to exploit this vulnerability upon HTML export. This significant security flaw was resolved in Etherpad version 3.3.0.

Affected Version(s)

etherpad < 3.3.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.