Cross-Site Scripting Vulnerability in Etherpad Real-Time Collaborative Editor
CVE-2026-55090
5.3MEDIUM
What is CVE-2026-55090?
A cross-site scripting vulnerability has been identified in Etherpad prior to version 3.3.0. The getHTMLFromAtext function improperly interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without adequate HTML attribute escaping. This allows an attacker to introduce malicious code that could execute when the manipulated HTML is rendered in the Etherpad environment. Notably, when bundled plugins like ep_font_color or ep_font_size are registered, they can facilitate the injection of attacker-controlled values, making it possible to exploit this vulnerability upon HTML export. This significant security flaw was resolved in Etherpad version 3.3.0.
Affected Version(s)
etherpad < 3.3.0
