GHSA-92hr-gmr6-h8cpMedium▾ SunlitEtherpad addressed weak token RNG, login timing, plugin path handling, API request handling
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Fix: PR #7906 (ether/etherpad). A set of medium/low hardening fixes:
Math.random() (client and server). Now use crypto.getRandomValues.crypto.timingSafeEqual plus a uniform failure delay; user lookup is own-property only./api/2 merged all request headers into the API field set. Now forwards only authorization, matching the openapi.ts handler.API.appendChatMessage could create arbitrary pads (missing getPadSafe). Now requires the pad to exist.ep_etherpad-lite <= 1.8.14Upgrade to a patched release:
ep_etherpad-lite 3.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55090HighEtherpad is a real-time collaborative editor
CVE-2026-55086Medium· 4.2Etherpad is a real-time collaborative editor
CVE-2026-55088Medium· 6.8Etherpad is a real-time collaborative editor
CVE-2026-55087Medium· 6.1Etherpad is a real-time collaborative editor
CVE-2026-54561Medium· 6.2MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants
CVE-2024-13986High· 8.8Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface