ep_etherpad-lite
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ep_etherpad-litepage 1 of 1
- CVE-2018-6835CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.6.32018-02-08
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
- CVE-2026-55086MEDIUMCVSS 4.2EG 4.2✓ Fixed in 3.1.02026-08-13
Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared worl…
- CVE-2026-55087MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.1.02026-08-13
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admin …
- CVE-2026-55088MEDIUMCVSS 6.8EG 6.8✓ Fixed in 3.1.02026-08-13
Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTrans…
- CVE-2026-55090MEDIUMCVSS 5.3EG 5.3✓ Fixed in 3.3.02026-08-17
Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute escap…
Check whether ep_etherpad-lite is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ep_etherpad-lite CVEs against the assets you own.
Start Free Scan →