Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Admin Configure Dialog Page Content
Published: September 02, 2026
SECURITY IDENTIFIERS
- GHSA: GHSA-4qhx-6wrv-5hg2
- Vendor Advisory: https://github.com/AlchemyCMS/alchemy_cms/security/advisories/GHSA-4qhx-6wrv-5hg2
GEM
SEVERITY
CVSS v3.x: 9.0 (Critical)
PATCHED VERSIONS
>= 8.3.8
DESCRIPTION
An improper input sanitization vulnerability in the menu node name rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the configure dialog for a page referencing the malicious node. The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation.
