VDB
Sign up

package

npm/ep_etherpad-lite

pkg:npm/ep_etherpad-lite

MEDIUM4.2npm
GHSA-2jwf-f4xq-f24h· CVE-2026-55086

ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite

Modified: 8/13/2026

MEDIUMnpm
GHSA-92hr-gmr6-h8cp

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

Modified: 8/17/2026

MEDIUM6.8npm
GHSA-vqfp-p66c-xrp9· CVE-2026-55088

ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token

Modified: 8/13/2026