Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Page Properties Configure Dialog
Published: September 02, 2026
SECURITY IDENTIFIERS
- GHSA: GHSA-g7vv-4mjj-6fgm
- Vendor Advisory: https://github.com/AlchemyCMS/alchemy_cms/security/advisories/GHSA-g7vv-4mjj-6fgm
GEM
SEVERITY
CVSS v3.x: 9.0 (Critical)
PATCHED VERSIONS
>= 8.3.8
DESCRIPTION
An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the Configure dialog for a page containing the malicious node. The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation.
