CRITICAL 9.6 CVE-2026-55085 Published 19 Aug 2026

Etherpad Cross-Site Scripting (XSS) Vulnerability

Worried this affects one of your servers?

Etherpad, a real-time collaborative editor, is affected by a Cross-Site Scripting (XSS) vulnerability.

Prior to version 3.3.1, Etherpad interpolates attacker-controlled data directly into HTML attributes, allowing an attacker to execute scripts when a user opens a malicious pad or uses the /timeslider feature.

Impact: Any user with write access to a pad can exploit this vulnerability, including administrators.

Affected Versions: All versions prior to 3.3.1

Mitigation: Upgrade to version 3.3.1 or later.

Reference: CVE-2026-55085 on NVD

← Back to Security News