RubySec

Providing security resources for the Ruby community

GHSA-4qhx-6wrv-5hg2 (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Admin Configure Dialog Page Content

Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Admin Configure Dialog Page Content

Published: September 02, 2026

SECURITY IDENTIFIERS

GEM

alchemy_cms

SEVERITY

CVSS v3.x: 9.0 (Critical)

PATCHED VERSIONS

>= 8.3.8

DESCRIPTION

An improper input sanitization vulnerability in the menu node name rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the configure dialog for a page referencing the malicious node. The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation.

RELATED