Skip to content

Stored XSS in Menu Node Name Rendered in Page Properties Configure Dialog

High
tvdeyen published GHSA-g7vv-4mjj-6fgm Sep 2, 2026

Package

bundler alchemy_cms (RubyGems)

Affected versions

< 8.3.8

Patched versions

>= 8.3.8

Description

An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the Configure dialog for a page containing the malicious node. The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation.

Note on duplication

This advisory and GHSA-4qhx-6wrv-5hg2 describe the same underlying defect: a menu node name rendered without escaping in an admin configure dialog. Both were reported by the same researchers and both were addressed in 8.3.8. They were published as two separate records and can no longer be withdrawn, so they are cross referenced here and should be counted as one issue.

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CVE ID

No known CVE

Weaknesses

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. Learn more on MITRE.

Credits