THREAT OPS › Threat News › [GHSA] GHSA-vqfp-p66c-xrp9 (medium) — ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
[GHSA] GHSA-vqfp-p66c-xrp9 (medium) — ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
GHSA-vqfp-p66c-xrp9 Severity: medium CVE: CVE-2026-55088
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Etherpad's device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token in the GET response body
## Description
Etherpad ships an endpoint pair unde
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-55088cve
- https://pad.example/tokenTransferurl
- https://pad.example/tokenTransfer/1f0b2a3c-url
Original source: https://github.com/advisories/GHSA-vqfp-p66c-xrp9