mediumCVSS 6.1Vulnerability

CVE-2026-55087

# GHSA-03 — `x-proxy-path` header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect) **Severity:** Medium **CVSS v3.1 vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N` **CVSS suggested base score:** ~6.1 — Medium *(Re-validate in the first.gov calculator before filing. Score depends heavily on whether you assume a cooperative cache exists in front of the deployment — single-origin admin-only ops with no shared cache push toward 4.x; cache-poisoning against a CDN pushes toward 7.x.)* **CWE:** CWE-79 Improper Neutralization of Input During Web Page Generation, CWE-601 URL Redirection to Untrusted Site, CWE-444 Inconsistent Interpretation of HTTP Requests ## Title `x-proxy-path` request header is interpolated into admin HTML/JS/CSS without sanitisation (cache-poisoning XSS) and into a `/p/:pad/timeslider` redirect target (open-redirect via protocol-relative URL) ## Description Etherpad lets operators run behind a reverse proxy that prefixes every route with a subpath (e.g. `/pad/etherpad/...`). The proxy is expected to set `x-proxy-path: /pad/etherpad` on every request so that server-rendered links, asset URLs, and redirects know to include the prefix. Two server-side call sites historically processed this header: ### Issue 3a — `src/node/hooks/express/admin.ts` (XSS, cache-poisoning) The admin static-serving handler read `req.header('x-proxy-path')` and substituted it into the response body of every `.html`/`.js`/`.css` asset under `/admin/*` using `String.prototype.replaceAll`. The value was used **raw**, with no character filter and no `Vary` / `Cache-Control` headers on the response. Consequently: - An attacker who can issue a request with a chosen `x-proxy-path` value gets that value reflected into HTML/JS/CSS sent back to them. **Reflected XSS** on the admin origin (requires victim to be tricked into issuing the request from a context that interprets HTML). - More seriously, any reverse proxy or

Properties

ghsa_id
GHSA-fjgc-3mj7-8rg8
severity
medium
summary
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
cvss_score
6.1
cve_id
CVE-2026-55087
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
is_ghsa_only
false
ghsa_published
2026-08-13T13:46:07Z
source_url
https://github.com/advisories/GHSA-fjgc-3mj7-8rg8
ghsa_updated
2026-08-13T13:46:08Z

Related Entities (6)

VULNERABLE_TO (1)

[Software]npm/ep_etherpad-lite

AFFECTS (1)

[Software]npm/ep_etherpad-lite

HAS_WEAKNESS (3)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
[Weakness]URL Redirection to Untrusted Site ('Open Redirect')
[Weakness]Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-55087 (CVSS 6.1) — Ninja Signal Threat Intelligence | Ninja Signal