CVE-2026-23885

CRITICAL CVSS 3.1: 9.9 EPSS 0.48%
Updated Apr 09, 2026
Alchemy-Cms
Parameter Value
CVSS 9.9 (CRITICAL)
Affected Versions 8.0.0 — 8.0.3
Fixed In 7.4.12
Type CWE-95
Vendor Alchemy-Cms
Public PoC No

Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3, the application uses the Ruby `eval()` function to dynamically execute a string provided by the `resource_handler.engine_name` attribute in `Alchemy::ResourcesHelper#resource_url_proxy`. The vulnerability exists in `app/helpers/alchemy/resources_helper.rb` at line 28.

The code explicitly bypasses security linting with `# rubocop:disable Security/Eval`, indicating that the use of a dangerous function was known but not properly mitigated. Since `engine_name` is sourced from module definitions that can be influenced by administrative configurations, it allows an authenticated attacker to escape the Ruby sandbox and execute arbitrary system commands on the host OS. Versions 7.4.12 and 8.0.3 fix the issue by replacing `eval()` with `send()`.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Alchemy-Cms Alchemy_Cms
cpe:2.3:a:alchemy-cms:alchemy_cms:*:*:*:*:*:*:*:*
— 7.4.12
Alchemy-Cms Alchemy_Cms
cpe:2.3:a:alchemy-cms:alchemy_cms:*:*:*:*:*:*:*:*
8.0.0 8.0.3

Related Vulnerabilities