Micro-Learning Gamification Platform Vulnerabilities in SkillTree by National Security Agency
CVE-2026-54694

9.6CRITICAL

Key Information:

Vendor
CVE Published:
9 September 2026

What is CVE-2026-54694?

SkillTree, created by the National Security Agency, suffers from two interconnected code flaws that culminate in a highly exploitable attack chain prior to its 4.4.2 release. The vulnerability stems from improper HTML sanitization in both the string rendering process within the StringHighlighter.js and the unfiltered input handling in the account registration endpoint. Attackers can exploit these weaknesses to execute cross-site scripting, load arbitrary scripts from external servers, or steal cross-site request forgery tokens without requiring additional user interaction. The complexity of these attacks arises from the escalating nature of their impact, enabling unauthorized actions such as project deletions and data exfiltration from the admin's browser. SkillTree has since patched this vulnerability in version 4.4.2.

Affected Version(s)

skills-service < 4.4.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.