Critical severity9.8NVD Advisory· Published Feb 8, 2018· Updated Jun 17, 2026
CVE-2018-6835
CVE-2018-6835
Description
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ep_etherpad-litenpm | < 1.6.3 | 1.6.3 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/ether/etherpad-lite/commit/626e58cc5af1db3691b41fca7b06c28ea43141b1nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-mvmv-rq2j-97p2ghsaADVISORY
- github.com/ether/etherpad-lite/releases/tag/1.6.3nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-6835ghsaADVISORY
News mentions
0No linked articles in our index yet.