CVE-2026-55085: Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite

Published Aug 19, 2026
·
Updated

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated markup to node.innerHTML. ImportEtherpad.setPadRaw in src/node/utils/ImportEtherpad.ts accepts attacker-controlled attribute-pool values from a crafted .etherpad import, including list:number1 and a malicious start value. Any user with write access to a pad can store markup that executes as cross-site scripting when another user opens the pad or /timeslider, including when an administrator views the pad. This issue is fixed in version 3.3.1.

Affected Software

1 affected component
Etherpad Etherpad<3.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade etherpad/etherpad-lite to a version that resolves this vulnerability.

    Fixed in 3.3.1

Event History

Aug 19, 2026
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Etherpad instances running versions before 3.3.1 are exposed when users can write to pads and another user later opens an affected pad or its /timeslider view. Administrators are also affected if they view a malicious pad.

2

What does an attacker need to exploit it?

An attacker needs write access to a pad and must import a crafted .etherpad file containing attacker-controlled attribute-pool values, including list:number1 with a malicious start value. Exploitation then requires another user to open the pad or /timeslider.

3

Is a default Etherpad installation affected?

The issue affects Etherpad versions prior to 3.3.1, but exploitation depends on an attacker being able to write to a pad and import a crafted .etherpad file. The provided information does not establish whether those conditions are enabled by default.

4

What can be done if upgrading is not immediately possible?

Restrict pad write access and prevent untrusted users from importing .etherpad files. Avoid opening pads or /timeslider views containing untrusted imported content, especially from administrator accounts.

5

How can I determine whether a pad may already be affected?

Review pads that were created or modified through .etherpad imports by untrusted writers, particularly imports containing list:number1 attribute-pool values with unusual start values. Opening a suspected pad or its /timeslider can trigger the stored script, so investigation should avoid privileged accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203