Micro-Learning Gamification Platform Vulnerabilities in SkillTree by National Security Agency
CVE-2026-54694
What is CVE-2026-54694?
SkillTree, created by the National Security Agency, suffers from two interconnected code flaws that culminate in a highly exploitable attack chain prior to its 4.4.2 release. The vulnerability stems from improper HTML sanitization in both the string rendering process within the StringHighlighter.js and the unfiltered input handling in the account registration endpoint. Attackers can exploit these weaknesses to execute cross-site scripting, load arbitrary scripts from external servers, or steal cross-site request forgery tokens without requiring additional user interaction. The complexity of these attacks arises from the escalating nature of their impact, enabling unauthorized actions such as project deletions and data exfiltration from the admin's browser. SkillTree has since patched this vulnerability in version 4.4.2.
Affected Version(s)
skills-service < 4.4.2
