RubySec

Providing security resources for the Ruby community

GHSA-g7vv-4mjj-6fgm (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Page Properties Configure Dialog

Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Page Properties Configure Dialog

Published: September 02, 2026

SECURITY IDENTIFIERS

GEM

alchemy_cms

SEVERITY

CVSS v3.x: 9.0 (Critical)

PATCHED VERSIONS

>= 8.3.8

DESCRIPTION

An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the Configure dialog for a page containing the malicious node. The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation.

RELATED