Listen to this Post
Fix: PR 7905 (ether/etherpad).
`getHTMLFromAtext` in `src/node/utils/ExportHtml.ts` interpolates values from the `exportHtmlAdditionalTagsWithData` plugin hook into `span data-ep_font_size), an attribute value such as `” onload=”alert(1)` is exported as `` and served as text/html, yielding stored XSS for any collaborator who opens the export.
The root cause is improper sanitization of attribute-pool values during HTML export. The export function blindly trusts user-controlled data from the pad’s attribute pool, which is populated via changesets that collaborators can manipulate. Because the `exportHtmlAdditionalTagsWithData` hook allows plugins to inject custom data attributes into exported HTML, a malicious user can craft a changeset that injects arbitrary attribute name/value pairs. When another user exports the pad to HTML, the unsanitized payload is written directly into the `span` tag’s attributes, breaking out of the intended `data-color` attribute and injecting an `onload` event handler. The exported file is served as text/html, meaning the browser will execute the injected JavaScript when the file is opened.
The vulnerability is stored (persistent) because the malicious payload resides in the pad’s attribute pool and affects all users who export that pad. No user interaction is required beyond opening the exported HTML file. The attack vector is network-based, requires no privileges, and has low complexity. The fix escapes both the name and value via Security.escapeHTMLAttribute. PR 7905 also adds a startup warning when default/placeholder account or SSO credentials are configured as a defense-in-depth measure.
DailyCVE Form:
Platform: Etherpad Lite
Version: < 3.3.0
Vulnerability: Stored XSS
Severity: Critical (CVSS 9.9)
date: 2026-08-17
Prediction: Patch released 2026-06-10 (v3.3.0)
What Undercode Say:
Check Etherpad version cat package.json | grep version Verify if vulnerable (versions prior to 3.3.0) npm list ep_etherpad-lite Check if exportHtmlAdditionalTagsWithData hook is registered grep -r "exportHtmlAdditionalTagsWithData" node_modules/ep_/index.js Identify bundled plugins that register the hook ls node_modules/ | grep -E "ep_font_color|ep_font_size"
Exploit: (Educational Purposes!)
Craft a changeset that injects a malicious attribute value into the pad’s attribute pool:
// Attacker-controlled changeset payload // Attribute value: " onload="alert(document.cookie) // This breaks out of the data-color attribute and injects an onload handler // The pad's attribute pool stores the unsanitized value via: // moveOpsToNewPool -> AttributePool.putAttrib(attribName, maliciousValue) // When exported, the HTML becomes: // <span data-color="" onload="alert(document.cookie)">text</span>
The exported HTML file, when opened by any collaborator, executes the injected JavaScript in their browser context.
Protection:
- Upgrade to Etherpad version 3.3.0 or later (includes PR 7905)
- Apply the fix: escape attribute names and values via `Security.escapeHTMLAttribute` in `ExportHtml.ts`
– Review any bundled plugins that register the `exportHtmlAdditionalTagsWithData` hook - Implement Content Security Policy (CSP) to mitigate XSS impact
- Set `HttpOnly` and `SameSite` attributes on cookies
Impact:
- Confidentiality: None (CVSS v4.0 VC:N)
- Integrity: High (VI:H) — attacker can execute arbitrary JavaScript in victims’ browsers
- Availability: None (VA:N)
- Stored XSS allows attackers to steal session cookies, perform actions on behalf of victims, or deface content
- Affects all collaborators who open an exported HTML file from a compromised pad
- No user interaction required beyond opening the exported file
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

