{"id":"CVE-2026-54064","aliases":["GHSA-465g-4q99-5x86"],"title":"NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module","summary":"NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module","severity":"high","cvss":8.7,"cwe":["CWE-79"],"vendor":"nukeviet","product":"nukeviet/nukeviet","ecosystem":"composer","affected":["nukeviet/nukeviet < 4.6.00"],"patched":["nukeviet/nukeviet 4.6.00"],"published":"2026-07-13","updated":"2026-07-13","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-465g-4q99-5x86","references":[{"url":"https://github.com/nukeviet/nukeviet/security/advisories/GHSA-465g-4q99-5x86"},{"url":"https://github.com/advisories/GHSA-465g-4q99-5x86"}],"tags":["ghsa","composer"],"ingestedAt":"2026-07-13T18:28:17.574Z","slug":"CVE-2026-54064","body":"## Overview\n\n## Summary\n\nTwo filter-bypass techniques in `NukeViet\\Core\\Request::filterAttr()` and `NukeViet\\Core\\Request::unhtmlentities()` allow a low-privileged user (any account with news post permission) to store and serve arbitrary JavaScript to any visitor of the affected page.\n\n## Affected Component\n\n`vendor/vinades/nukeviet/Core/Request.php` — class `NukeViet\\Core\\Request`\n\n## Vulnerability Details\n\n### Bypass 1 — Form Feed character prefix (`\\x0C`) before event handler name\n\nThe `filterAttr()` method blocks event-handler attributes using:\n```php\npreg_match('/^on/i', $attrSubSet[0])\n```\nPHP's `trim()` does **not** strip the ASCII Form Feed character (`\\x0C`, U+000C). An attacker can prefix the attribute name with `\\x0C` so that `\\x0Conerror` does not match `/^on/`. The HTML5 browser parser treats `\\x0C` as a valid whitespace separator and correctly activates the event handler.\n\n**Proof-of-concept payload (URL-encoded POST body field `bodyhtml`):**\n```\n<img src=\"x\" %0Conerror=\"alert('XSS')\">\n```\n\n### Bypass 2 — Decimal HTML entity tab (`&#9;`) inside `javascript:` URI\n\n`unhtmlentities()` strips the hex-encoded tab `&#x09;` via `str_ireplace`, but did **not** strip its decimal equivalent `&#9;`. The keyword-blocking regex `/j\\s*a\\s*v\\s*a\\s*s\\s*c\\s*r\\s*i\\s*p\\s*t/si` uses `\\s*` which does not match HTML entities. The value `jav&#9;ascript:alert()` passes the filter, is stored in the database, and is decoded by the browser into a working `javascript:` URI.\n\n**Proof-of-concept payload (inside a Markdown-style link):**\n```\n[Click me](jav&#9;ascript:alert('XSS'))\n```\n\n## Impact\n\nAn authenticated attacker with news-posting permission can inject persistent JavaScript that executes in the browser of **any user** (including administrators) who views the affected article. This enables session cookie theft, credential harvesting, defacement, and further privilege escalation.\n\n## Patches\n\nFixed in commit `<commit-sha>` by modifying `vendor/vinades/nukeviet/Core/Request.php`:\n\n1. **`filterAttr()`** — strip all ASCII control characters (`\\x00`–`\\x20`) from the attribute name before the `/^on/` check:\n   ```php\n   $attrSubSet[0] = preg_replace('/[\\x00-\\x20]/', '', strtolower($attrSubSet[0]));\n   ```\n\n2. **`unhtmlentities()`** — strip decimal HTML entities for all ASCII control characters (0–31) before the keyword checks:\n   ```php\n   $value = preg_replace('/&#0*(?:3[01]|[12][0-9]|[0-9]);/', '', $value);\n   ```\n\n## Workarounds\n\nNone. Update to the patched version.\n\n## Resources\n\n- CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)\n- OWASP WSTG-INPV-02: Testing for Stored Cross Site Scripting\n- [OWASP Top 10 A03:2021 – Injection](https://owasp.org/Top10/A03_2021-Injection/)\n\n## Affected packages\n\n- `nukeviet/nukeviet < 4.6.00`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nukeviet/nukeviet 4.6.00`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}