ep_etherpad-lite
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ep_etherpad-litepage 1 of 1
- CVE-2018-6835CRITICALCVSS 9.8EG 9.8fixed in 1.6.32018-02-08
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
- CVE-2026-55086MEDIUMCVSS 4.2EG 4.2fixed in 3.1.02026-08-13
Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared worl…
- CVE-2026-55087MEDIUMCVSS 6.1EG 6.1fixed in 3.1.02026-08-13
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admin …
- CVE-2026-55088MEDIUMCVSS 6.8EG 6.8fixed in 3.1.02026-08-13
Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTrans…
- CVE-2026-55090MEDIUMCVSS 5.3EG 5.3fixed in 3.3.02026-08-17
Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute escap…
Check whether ep_etherpad-lite is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ep_etherpad-lite CVEs against the assets you own.
Book a Demo →