What is CVE-2026-55090?
This vulnerability exists in Etherpad real-time collaborative editor. In versions prior to 3.3.0, the `getHTMLFromAtext` function interpolates plugin hook values into span data attributes without proper HTML attribute escaping, leading to potential XSS attacks. Developers must upgrade to version 3.3.0 or later immediately, while users should avoid editing pads from untrusted sources.
Azərbaycanca: Bu boşluq Etherpad real-vaxt əməkdaşlıq redaktorunda aşkarlanıb. 3.3.0 versiyasından əvvəlki versiyalarda `getHTMLFromAtext` funksiyası plagin məlumatlarını HTML atributlarından qaçırmadan işləyir və nəticədə XSS hücumlarına yol açır. Tərtibatçılar dərhal Etherpad-i ən son versiyaya yeniləməli, istifadəçilər isə etibarsız redaktorlara diqqət yetirməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of Etherpad are affected by CVE-2026-55090?
All Etherpad versions prior to 3.3.0 are affected by this XSS vulnerability.
What is the root cause of CVE-2026-55090 vulnerability?
The `getHTMLFromAtext` function improperly interpolates plugin hook values into span data attributes without proper HTML attribute escaping, leading to XSS attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.