CVE-2026-54694 | NationalSecurityAgency skills-service up to 4.4.1 Account Registration Endpoint StringHighlighter.js eval firstName/lastName/nickname input validation
A vulnerability was found in NationalSecurityAgency skills-service up to 4.4.1. It has been rated as critical. This affects the function eval of the file StringHighlighter.js of the component Account Registration Endpoint. The manipulation of the argument firstName/lastName/nickname leads to improper input validation.
This vulnerability is traded as CVE-2026-54694. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More