CRITICAL
9.6 CVE-2026-55085 Published 19 Aug 2026
Etherpad Cross-Site Scripting (XSS) Vulnerability
Worried this affects one of your servers?
Etherpad, a real-time collaborative editor, is affected by a Cross-Site Scripting (XSS) vulnerability.
Prior to version 3.3.1, Etherpad interpolates attacker-controlled data directly into HTML attributes, allowing an attacker to execute scripts when a user opens a malicious pad or uses the /timeslider feature.
Impact: Any user with write access to a pad can exploit this vulnerability, including administrators.
Affected Versions: All versions prior to 3.3.1
Mitigation: Upgrade to version 3.3.1 or later.
Reference: CVE-2026-55085 on NVD
← Back to Security News