Feed/CVE-2026-55090
CVE-2026-55090HIGHCVSS 0.0

Etherpad has stored XSS in HTML export via unescaped attribute-pool values

Published Aug 17, 2026·Updated Aug 17, 2026

NVD Description

Fix: PR #7905 (ether/etherpad). `getHTMLFromAtext` in `src/node/utils/ExportHtml.ts` interpolates values from the `exportHtmlAdditionalTagsWithData` plugin hook into `span data-<k>="<v>"` without HTML-attribute escaping. The value comes verbatim from the pad attribute pool, which a pad editor controls via a crafted changeset (only `author` attributes are validated; `moveOpsToNewPool` -> `AttributePool.putAttrib` stores any value). With a bundled plugin that registers the hook (ep_font_color / ep_font_size), an attribute value such as `" onload="alert(1)` is exported as `<span data-color="" onload="alert(1)">` and served as text/html, yielding stored XSS for any collaborator who opens the export. Fix: escape the name and value via `Security.escapeHTMLAttribute`. PR #7905 also adds a startup warning when default/placeholder account or SSO credentials are configured (defense-in-depth, non-breaking).

Affected Packages (1)

ep_etherpad-liteNPM
Fixed in = 1.8.14

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free