CVE-2026-55087
unknown
CVSS v3
—
CVSS v4 NEW
—
VIR risk
—
Description
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | ep_etherpad-lite | >=2.1.0,<3.1.0 | 3.1.0 |
References
- https://github.com/ether/etherpad/security/advisories/GHSA-fjgc-3mj7-8rg8
- https://github.com/ether/etherpad/pull/6399
- https://github.com/ether/etherpad/pull/7710
- https://github.com/ether/etherpad/pull/7784
- https://github.com/ether/etherpad/commit/451bd9c3ebb0dded99dd0ff21811ee00e0940c29
- https://github.com/ether/etherpad/commit/63e9b2d4eb303cd341022591bdf9484584db36e3
- https://github.com/ether/etherpad
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.