logo

What's Bugging the NSA? A Vuln in Its 'SkillTree' Training Platform

ID: 692a6346-9474-50e5-85a3-a027f0747c28

STIX ID: report--692a6346-9474-50e5-85a3-a027f0747c28

Feed Name: Dark Reading

Threat Score
30/100

Date Published: 2024-07-10

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

The NSA patched a CSRF vulnerability (CVE-2024-39326) in its open-source SkillTree platform that could have allowed an attacker who convinced an admin to click a malicious link to modify videos, captions, and lesson text; the flaw has a CVSS score of 4.4, was reported by Contrast on June 12, and was fixed on July 2 with no reported data exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.