Please email [email protected] to report security related issues.
Security: ether/etherpad
Security
SECURITY.md
-
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-liteGHSA-f7h5-v9hm-548j published
Jun 10, 2026 by JohnMcLearCritical -
Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwriteGHSA-2jwf-f4xq-f24h published
Jun 10, 2026 by JohnMcLearModerate -
x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)GHSA-fjgc-3mj7-8rg8 published
Jun 10, 2026 by JohnMcLearModerate -
Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author tokenGHSA-vqfp-p66c-xrp9 published
Jun 10, 2026 by JohnMcLearModerate -
JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpointGHSA-qfmh-fph3-mw8q published
Jun 10, 2026 by JohnMcLearCritical -
Hardening: weak token RNG, login timing, plugin path handling, API request handlingGHSA-92hr-gmr6-h8cp published
Jun 10, 2026 by JohnMcLearModerate -
Stored XSS in HTML export via unescaped attribute-pool valuesGHSA-2jp7-wwpg-3p9w published
Jun 10, 2026 by JohnMcLearHigh -
Admin privilege escalation and arbitrary code execution via malicious *.etherpad importsGHSA-w3g3-qf3g-2mqc published
Dec 9, 2021 by rhansenCritical
Learn more about advisories related to ether/etherpad in the GitHub Advisory Database