Vulnary
← back to the feed
Critical· 9.6official fix available

CVE-2026-54694

SkillTree, a micro‑learning platform, has a critical flaw that lets an attacker inject malicious HTML and JavaScript through user registration fields. The unsanitized input is later rendered with Vue’s v‑html, allowing the attacker to run arbitrary code in an administrator’s browser. The vulnerability also enables remote script loading and cross‑site request forgery token theft without any phishing or admin interaction.

publishedSep 9, 2026
last modifiedSep 10, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
21th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 9, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

SkillTree versions earlier than 4.4.2. Administrators who view quiz runs and users who can register accounts are affected.

02

Real-world impact

An attacker can execute arbitrary JavaScript in an admin’s browser, load malicious scripts from their own server, delete or create projects, create backdoor accounts, dump user data, install keyloggers, and steal XSRF tokens to perform privileged actions on the platform.

03

Why this severity

The CVSS score of 9.6 reflects a network‑accessible attack (AV:N) that requires low effort (AC:L) and no privileges (PR:N). The vulnerability changes the scope (S:C) and allows high confidentiality and integrity impact, while availability is only low. The UI requirement (UI:R) means the attacker must trick an admin into viewing a page, but the exploit chain is automatic once the admin opens the quiz runs page.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade SkillTree to version 4.4.2 or later.

NVD description

05

Timeline

  1. Sep 9, 2026 · 4d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Sep 9, 2026 · 4d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactLow
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →