CRITICAL
9.6 CVE-2026-54694 Published 9 Sept 2026
SkillTree XSS & RCE Vulnerability
Worried this affects one of your servers?
SkillTree, a micro-learning platform, had a critical security flaw in versions prior to 4.4.2.
StringHighlighter.js built HTML strings without proper encoding, and HighlightedValue.vue rendered them via v-html, leading to cross-site scripting (XSS). Additionally, the account registration endpoint accepted unsanitized input, allowing remote code execution (RCE) and cross-site request forgery (CSRF) token theft.
- Impact: XSS, RCE, CSRF
- Affected: All versions prior to 4.4.2
- Mitigation: Upgrade to version 4.4.2
Reference: CVE-2026-54694 on NVD
← Back to Security News