An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
https://github.com/ether/etherpad-lite/releases
https://blog.sonarsource.com/etherpad-code-execution-vulnerabilities