{"id":"GHSA-92hr-gmr6-h8cp","title":"Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling","summary":"Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling","severity":"medium","cwe":["CWE-22","CWE-208","CWE-209","CWE-235","CWE-330"],"vendor":"ep_etherpad-lite","product":"ep_etherpad-lite","ecosystem":"npm","affected":["ep_etherpad-lite <= 1.8.14"],"patched":["ep_etherpad-lite 3.3.0"],"published":"2026-08-17","updated":"2026-08-17","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-92hr-gmr6-h8cp","references":[{"url":"https://github.com/ether/etherpad/security/advisories/GHSA-92hr-gmr6-h8cp"},{"url":"https://github.com/ether/etherpad/pull/7906"},{"url":"https://github.com/ether/etherpad/commit/7ea99706483443239bbbc0f2df9aff8ab5de4805"},{"url":"https://github.com/ether/etherpad/releases/tag/3.3.0"},{"url":"https://github.com/advisories/GHSA-92hr-gmr6-h8cp"}],"tags":["ghsa","npm"],"ingestedAt":"2026-08-17T17:58:10.291Z","slug":"GHSA-92hr-gmr6-h8cp","body":"## Overview\n\nFix: PR #7906 (ether/etherpad). A set of medium/low hardening fixes:\n\n- **Weak RNG for tokens (CWE-330):** author/session/readonly IDs were generated with `Math.random()` (client and server). Now use `crypto.getRandomValues`.\n- **Login timing / no failure delay (CWE-208/CWE-307):** the OIDC interaction login used a non-constant-time password compare with no failure delay. Now uses `crypto.timingSafeEqual` plus a uniform failure delay; user lookup is own-property only.\n- **Plugin dependency path handling (CWE-22):** plugin dependency names from package.json were used to build filesystem paths without validation (admin-gated install). Now validated against the npm name grammar.\n- **API parameter pollution (CWE-235):** `/api/2` merged all request headers into the API field set. Now forwards only `authorization`, matching the openapi.ts handler.\n- **Pad-creation side effect:** `API.appendChatMessage` could create arbitrary pads (missing `getPadSafe`). Now requires the pad to exist.\n- **Error info disclosure (CWE-209):** the admin file server echoed filesystem error detail; now returns a generic message.\n\n## Affected packages\n\n- `ep_etherpad-lite <= 1.8.14`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `ep_etherpad-lite 3.3.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}