{"id":"CVE-2026-55090","summary":"Etherpad: Stored XSS in HTML export via unescaped attribute-pool values","details":"Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute escaping. A pad editor can place an attacker-controlled value into the attribute pool through moveOpsToNewPool and AttributePool.putAttrib. When a bundled plugin such as ep_font_color or ep_font_size registers the hook, opening the resulting HTML export causes the value to execute as stored cross-site scripting in the Etherpad origin. This issue is fixed in version 3.3.0.","aliases":["GHSA-2jp7-wwpg-3p9w"],"modified":"2026-09-11T03:30:41.668435485Z","published":"2026-08-19T19:32:17.607Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55090.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/ether/etherpad/releases/tag/v3.3.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55090.json"},{"type":"ADVISORY","url":"https://github.com/ether/etherpad/security/advisories/GHSA-2jp7-wwpg-3p9w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55090"},{"type":"FIX","url":"https://github.com/ether/etherpad/commit/86c56cf827dd6e5ff1b6cd3760f87adc47f58bb1"},{"type":"FIX","url":"https://github.com/ether/etherpad/pull/7905"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ether/etherpad","events":[{"introduced":"0"},{"fixed":"86c56cf827dd6e5ff1b6cd3760f87adc47f58bb1"},{"fixed":"67f7d914f4e40f7cfda229c4865386deeb3c3c2b"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"3.3.0"}]}}],"versions":["v3.2.0","3.2.0","v3.1.0","3.1.0","v3.0.0","3.0.0","v2.7.3","2.7.3","v2.7.2","2.7.2","v2.7.1","2.7.1","v2.7.0","2.7.0","v2.6.1","2.6.1","v2.6.0","2.6.0","v2.5.3","2.5.3","v2.5.1","2.5.1","v2.5.0","2.5.0","v2.4.2","2.4.2","v2.4.1","2.4.1","v2.4.0","2.4.0","v2.3.2","2.3.2","v2.3.1","2.3.1","v2.3.0","2.3.0","v2.2.7","2.2.7","v2.2.6","2.2.6","v2.2.5","2.2.5","v2.2.4","2.2.4","v2.2.3","2.2.3","v2.2.2","2.2.2","v2.2.1","2.2.1","v2.2.0","2.2.0","v2.1.1","2.1.1","v2.1.0","2.1.0","v2.0.3","2.0.3","v2.0.2","2.0.2","v2.0.1","2.0.1","v2.0.0","2.0.0","v1.9.7","1.9.7","v1.9.6","1.9.6","v1.9.5","1.9.5","v1.9.4","1.9.4","1.9.3","v1.9.3","1.9.2","v1.9.2","1.8.15","v1.9.1","1.9.1","v1.9.0","1.9.0","1.8.18","1.8.17","1.8.16","1.8.14","1.8.13","1.8.12","1.8.11","1.8.10","1.8.9","1.8.8","1.8.7","1.8.6","1.6.2","1.6.1","1.6.0","1.5.7","1.5.6","1.5.5","1.5.4","1.5.3","1.5.2","1.5.1","1.4.1","1.4.0","1.3.0","1.2.12","1.2.9","1.2.7","1.2.6","1.2.5","1.2.4","1.2.3","1.2.2","1.2.1","1.2.0","1.1.5","1.1.4","1.1.3","1.1.2","1.1.1","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55090.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}