CRITICAL 9.6 CVE-2026-54694 Published 9 Sept 2026

SkillTree XSS & RCE Vulnerability

Worried this affects one of your servers?

SkillTree, a micro-learning platform, had a critical security flaw in versions prior to 4.4.2.

StringHighlighter.js built HTML strings without proper encoding, and HighlightedValue.vue rendered them via v-html, leading to cross-site scripting (XSS). Additionally, the account registration endpoint accepted unsanitized input, allowing remote code execution (RCE) and cross-site request forgery (CSRF) token theft.

  • Impact: XSS, RCE, CSRF
  • Affected: All versions prior to 4.4.2
  • Mitigation: Upgrade to version 4.4.2

Reference: CVE-2026-54694 on NVD

← Back to Security News