Etherpad Stored XSS in HTML Export via Unescaped Attribute-Pool Values, CVE-2026-55090 (Critical) -DC-Aug2026-1546

Listen to this Post

Fix: PR 7905 (ether/etherpad).

`getHTMLFromAtext` in `src/node/utils/ExportHtml.ts` interpolates values from the `exportHtmlAdditionalTagsWithData` plugin hook into `span data-=”“` without HTML-attribute escaping. The value comes verbatim from the pad attribute pool, which a pad editor controls via a crafted changeset—only author attributes are validated; `moveOpsToNewPool` -> `AttributePool.putAttrib` stores any value. With a bundled plugin that registers the hook (e.g., `ep_font_color` or ep_font_size), an attribute value such as `” onload=”alert(1)` is exported as `` and served as text/html, yielding stored XSS for any collaborator who opens the export.
The root cause is improper sanitization of attribute-pool values during HTML export. The export function blindly trusts user-controlled data from the pad’s attribute pool, which is populated via changesets that collaborators can manipulate. Because the `exportHtmlAdditionalTagsWithData` hook allows plugins to inject custom data attributes into exported HTML, a malicious user can craft a changeset that injects arbitrary attribute name/value pairs. When another user exports the pad to HTML, the unsanitized payload is written directly into the `span` tag’s attributes, breaking out of the intended `data-color` attribute and injecting an `onload` event handler. The exported file is served as text/html, meaning the browser will execute the injected JavaScript when the file is opened.
The vulnerability is stored (persistent) because the malicious payload resides in the pad’s attribute pool and affects all users who export that pad. No user interaction is required beyond opening the exported HTML file. The attack vector is network-based, requires no privileges, and has low complexity. The fix escapes both the name and value via Security.escapeHTMLAttribute. PR 7905 also adds a startup warning when default/placeholder account or SSO credentials are configured as a defense-in-depth measure.

DailyCVE Form:

Platform: Etherpad Lite
Version: < 3.3.0
Vulnerability: Stored XSS
Severity: Critical (CVSS 9.9)
date: 2026-08-17

Prediction: Patch released 2026-06-10 (v3.3.0)

What Undercode Say:

Check Etherpad version
cat package.json | grep version
Verify if vulnerable (versions prior to 3.3.0)
npm list ep_etherpad-lite
Check if exportHtmlAdditionalTagsWithData hook is registered
grep -r "exportHtmlAdditionalTagsWithData" node_modules/ep_/index.js
Identify bundled plugins that register the hook
ls node_modules/ | grep -E "ep_font_color|ep_font_size"

Exploit: (Educational Purposes!)

Craft a changeset that injects a malicious attribute value into the pad’s attribute pool:

// Attacker-controlled changeset payload
// Attribute value: " onload="alert(document.cookie)
// This breaks out of the data-color attribute and injects an onload handler
// The pad's attribute pool stores the unsanitized value via:
// moveOpsToNewPool -> AttributePool.putAttrib(attribName, maliciousValue)
// When exported, the HTML becomes:
// <span data-color="" onload="alert(document.cookie)">text</span>

The exported HTML file, when opened by any collaborator, executes the injected JavaScript in their browser context.

Protection:

  • Upgrade to Etherpad version 3.3.0 or later (includes PR 7905)
  • Apply the fix: escape attribute names and values via `Security.escapeHTMLAttribute` in `ExportHtml.ts`
    – Review any bundled plugins that register the `exportHtmlAdditionalTagsWithData` hook
  • Implement Content Security Policy (CSP) to mitigate XSS impact
  • Set `HttpOnly` and `SameSite` attributes on cookies

Impact:

  • Confidentiality: None (CVSS v4.0 VC:N)
  • Integrity: High (VI:H) — attacker can execute arbitrary JavaScript in victims’ browsers
  • Availability: None (VA:N)
  • Stored XSS allows attackers to steal session cookies, perform actions on behalf of victims, or deface content
  • Affects all collaborators who open an exported HTML file from a compromised pad
  • No user interaction required beyond opening the exported file

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top