{"id":"GHSA-465g-4q99-5x86","summary":"NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module","details":"## Summary\n\nTwo filter-bypass techniques in `NukeViet\\Core\\Request::filterAttr()` and `NukeViet\\Core\\Request::unhtmlentities()` allow a low-privileged user (any account with news post permission) to store and serve arbitrary JavaScript to any visitor of the affected page.\n\n## Affected Component\n\n`vendor/vinades/nukeviet/Core/Request.php` — class `NukeViet\\Core\\Request`\n\n## Vulnerability Details\n\n### Bypass 1 — Form Feed character prefix (`\\x0C`) before event handler name\n\nThe `filterAttr()` method blocks event-handler attributes using:\n```php\npreg_match('/^on/i', $attrSubSet[0])\n```\nPHP's `trim()` does **not** strip the ASCII Form Feed character (`\\x0C`, U+000C). An attacker can prefix the attribute name with `\\x0C` so that `\\x0Conerror` does not match `/^on/`. The HTML5 browser parser treats `\\x0C` as a valid whitespace separator and correctly activates the event handler.\n\n**Proof-of-concept payload (URL-encoded POST body field `bodyhtml`):**\n```\n\u003cimg src=\"x\" %0Conerror=\"alert('XSS')\"\u003e\n```\n\n### Bypass 2 — Decimal HTML entity tab (`&#9;`) inside `javascript:` URI\n\n`unhtmlentities()` strips the hex-encoded tab `&#x09;` via `str_ireplace`, but did **not** strip its decimal equivalent `&#9;`. The keyword-blocking regex `/j\\s*a\\s*v\\s*a\\s*s\\s*c\\s*r\\s*i\\s*p\\s*t/si` uses `\\s*` which does not match HTML entities. The value `jav&#9;ascript:alert()` passes the filter, is stored in the database, and is decoded by the browser into a working `javascript:` URI.\n\n**Proof-of-concept payload (inside a Markdown-style link):**\n```\n[Click me](jav&#9;ascript:alert('XSS'))\n```\n\n## Impact\n\nAn authenticated attacker with news-posting permission can inject persistent JavaScript that executes in the browser of **any user** (including administrators) who views the affected article. This enables session cookie theft, credential harvesting, defacement, and further privilege escalation.\n\n## Patches\n\nFixed in commit `\u003ccommit-sha\u003e` by modifying `vendor/vinades/nukeviet/Core/Request.php`:\n\n1. **`filterAttr()`** — strip all ASCII control characters (`\\x00`–`\\x20`) from the attribute name before the `/^on/` check:\n   ```php\n   $attrSubSet[0] = preg_replace('/[\\x00-\\x20]/', '', strtolower($attrSubSet[0]));\n   ```\n\n2. **`unhtmlentities()`** — strip decimal HTML entities for all ASCII control characters (0–31) before the keyword checks:\n   ```php\n   $value = preg_replace('/&#0*(?:3[01]|[12][0-9]|[0-9]);/', '', $value);\n   ```\n\n## Workarounds\n\nNone. Update to the patched version.\n\n## Resources\n\n- CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)\n- OWASP WSTG-INPV-02: Testing for Stored Cross Site Scripting\n- [OWASP Top 10 A03:2021 – Injection](https://owasp.org/Top10/A03_2021-Injection/)","aliases":["CVE-2026-54064"],"modified":"2026-07-13T18:11:45.647263Z","published":"2026-07-13T17:54:08Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-13T17:54:08Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/nukeviet/nukeviet/security/advisories/GHSA-465g-4q99-5x86"},{"type":"PACKAGE","url":"https://github.com/nukeviet/nukeviet"}],"affected":[{"package":{"name":"nukeviet/nukeviet","ecosystem":"Packagist","purl":"pkg:composer/nukeviet/nukeviet"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.00"}]}],"versions":["4.0.24","4.4.01"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-465g-4q99-5x86/GHSA-465g-4q99-5x86.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}