ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
- Severity:
- Medium
Description
Severity: Medium CVSS v3.1 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS suggested base score: ~6.1 — Medium *(Re-validate in the first.gov calculator before filing.
Recommendation
Update the ep_etherpad-lite package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.1.0, <= 3.0.0
- Patched version(s): 3.1.0
References
- GHSA-fjgc-3mj7-8rg8
- CVE-2026-55087
- CWE-444
- CWE-601
- CWE-79
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A3
- OWASP 2021-A4
- OWASP 2021-A6
Related Issues
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- Svelte affected by cross-site scripting via spread attributes in Svelte SSR - CVE-2026-27121
- Svelte SSR vulnerable to cross-site scripting via spread attributes - CVE-2026-42599
- showdown allows stored cross-site scripting through table header ID injection - CVE-2026-59710
You might also like:
- Tags:
- npm
- ep_etherpad-lite
Anything's wrong? Let us know Last updated on August 13, 2026


