What is CVE-2026-55087?
This vulnerability allows XSS in Etherpad's admin panel via the unsanitized x-proxy-path header, enabling attacker code injection. Versions 2.1.0 through 3.1.0 are affected; users must update immediately or apply header filtering.
Azərbaycanca: Bu boşluq Etherpad-in admin panelində XSS-ə yol açır: x-proxy-path başlığı sanitizə olunmadığı üçün təcavüzkar kod inyeksiya edə bilər. 2.1.0-dan 3.1.0-a qədər versiyalar təsirlənir; istifadəçilər dərhal yenilənməli və ya header filtrasiyası tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which product is affected by CVE-2026-55087?
This vulnerability affects the Etherpad application.
To which versions should one update to be protected from CVE-2026-55087?
The affected versions are 2.1.0 through 3.1.0. Users must immediately update to a version newer than this range.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.