An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-34816.json"