Threat Advisory

Etherpad Vulnerabilities Affect Control Panels and Account Secrets

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Etherpad Lite is affected by two vulnerabilities. The first issue involves improper handling of the x-proxy-path HTTP header, where unsanitized input can be reflected into admin HTML/JS/CSS responses, enabling cache-poisoning-based cross-site scripting (XSS), and can also be abused to perform open redirects through crafted protocol-relative URLs. The second vulnerability affects the device-to-device author-token transfer mechanism, where token transfer links lack expiration and single-use restrictions while exposing the raw author token in API responses, allowing attackers who obtain transfer identifiers to perform persistent account impersonation. Both vulnerabilities are addressed through input sanitization, cache protections, token expiration, single-use enforcement, and removal of sensitive token exposure.

CVE-2026-55088 (CVSS 6.8 — Medium): Etherpad Lite contains an author-token transfer vulnerability where the /tokenTransfer endpoint lacks token expiration and single-use enforcement while exposing raw author tokens in responses, allowing attackers with a leaked transfer identifier to perform persistent account impersonation.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Etherpad Lite is affected by two vulnerabilities. The first issue involves improper handling of the x-proxy-path HTTP header, where unsanitized input can be reflected into admin HTML/JS/CSS responses, enabling cache-poisoning-based cross-site scripting (XSS), and can also be abused to perform open redirects through crafted protocol-relative URLs. The second vulnerability affects the device-to-device author-token transfer mechanism, where token transfer links lack expiration and single-use restrictions while exposing the raw author token in API responses, allowing attackers who obtain transfer identifiers to perform persistent account impersonation. Both vulnerabilities are addressed through input sanitization, cache protections, token expiration, single-use enforcement, and removal of sensitive token exposure.

CVE-2026-55088 (CVSS 6.8 — Medium): Etherpad Lite contains an author-token transfer vulnerability where the /tokenTransfer endpoint lacks token expiration and single-use enforcement while exposing raw author tokens in responses, allowing attackers with a leaked transfer identifier to perform persistent account impersonation.[emaillocker id="1283"]

CVE-2026-55088 (CVSS 6.1 — Medium): Etherpad Lite contains an x-proxy-path header handling flaw that allows attackers to inject unsanitized content into admin HTML/JS/CSS responses for cache-poisoning XSS and exploit crafted redirect URLs for open redirect attacks.

RECOMMENDATION:

We recommend you to update ep_etherpad-lite to version 3.3.3 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu