{"id":"CVE-2026-54064","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54064","summary":"NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module","details":"## Summary\n\nTwo filter-bypass techniques in `NukeViet\\Core\\Request::filterAttr()` and `NukeViet\\Core\\Request::unhtmlentities()` allow a low-privileged user (any account with news post permission) to store and serve arbitrary JavaScript to any visitor of the affected page.\n\n## Affected Component\n\n`vendor/vinades/nukeviet/Core/Request.php` — class `NukeViet\\Core\\Request`\n\n## Vulnerability Details\n\n### Bypass 1 — Form Feed character prefix (`\\x0C`) before event handler name\n\nThe `filterAttr()` method blocks event-handler attributes using:\n```php\npreg_match('/^on/i', $attrSubSet[0])\n```\nPHP's `trim()` does **not** strip the ASCII Form Feed character (`\\x0C`, U+000C). An attacker can prefix the attribute name with `\\x0C` so that `\\x0Conerror` does not match `/^on/`. The HTML5 browser parser treats `\\x0C` as a valid whitespace separator and correctly activates the event handler.\n\n**Proof-of-concept payload (URL-encoded POST body field `bodyhtml`):**\n```\n<img src=\"x\" %0Conerror=\"alert('XSS')\">\n```\n\n### Bypass 2 — Decimal HTML entity tab (`&#9;`) inside `javascript:` URI\n\n`unhtmlentities()` strips the hex-encoded tab `&#x09;` via `str_ireplace`, but did **not** strip its decimal equivalent `&#9;`. The keyword-blocking regex `/j\\s*a\\s*v\\s*a\\s*s\\s*c\\s*r\\s*i\\s*p\\s*t/si` uses `\\s*` which does not match HTML entities. The value `jav&#9;ascript:alert()` passes the filter, is stored in the database, and is decoded by the browser into a working `javascript:` URI.\n\n**Proof-of-concept payload (inside a Markdown-style link):**\n```\n[Click me](jav&#9;ascript:alert('XSS'))\n```\n\n## Impact\n\nAn authenticated attacker with news-posting permission can inject persistent JavaScript that executes in the browser of **any user** (including administrators) who views the affected article. This enables session cookie theft, credential harvesting, defacement, and further privilege escalation.\n\n## Patches\n\nFixed in commit `<commit-sha>` by modifying `vendor/vinades/nukeviet/Core/Request.php`:\n\n1. **`filterAttr()`** — strip all ASCII control characters (`\\x00`–`\\x20`) from the attribute name before the `/^on/` check:\n   ```php\n   $attrSubSet[0] = preg_replace('/[\\x00-\\x20]/', '', strtolower($attrSubSet[0]));\n   ```\n\n2. **`unhtmlentities()`** — strip decimal HTML entities for all ASCII control characters (0–31) before the keyword checks:\n   ```php\n   $value = preg_replace('/&#0*(?:3[01]|[12][0-9]|[0-9]);/', '', $value);\n   ```\n\n## Workarounds\n\nNone. Update to the patched version.\n\n## Resources\n\n- CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)\n- OWASP WSTG-INPV-02: Testing for Stored Cross Site Scripting\n- [OWASP Top 10 A03:2021 – Injection](https://owasp.org/Top10/A03_2021-Injection/)","published":"2026-07-13T17:54:08Z","modified":"2026-07-13T18:11:45.647263Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"nukeviet/nukeviet","fixedVersion":"4.6.00"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/nukeviet/nukeviet/security/advisories/GHSA-465g-4q99-5x86"},{"type":"PACKAGE","url":"https://github.com/nukeviet/nukeviet"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T18:11:45.647263Z"}}