THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2jp7-wwpg-3p9w (high) — Etherpad has stored XSS in HTML export via unescaped attribute-pool values

[GHSA] GHSA-2jp7-wwpg-3p9w (high) — Etherpad has stored XSS in HTML export via unescaped attribute-pool values

medgithub_advisoriesPublished 2026-08-17

GHSA-2jp7-wwpg-3p9w Severity: high CVE: CVE-2026-55090

Etherpad has stored XSS in HTML export via unescaped attribute-pool values

Fix: PR #7905 (ether/etherpad).

`getHTMLFromAtext` in `src/node/utils/ExportHtml.ts` interpolates values from the `exportHtmlAdditionalTagsWithData` plugin hook into `span data-<k>="<v>"` without HTML-attribute escaping. The value comes verbatim from the pad attribut

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2jp7-wwpg-3p9w