Vulnerabilities/

ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartex

Severity:
Medium

Description

Etherpad’s device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token in the GET response body

Recommendation

Update the ep_etherpad-lite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ep_etherpad-lite
Anything's wrong? Let us know Last updated on August 13, 2026