Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-23885

Опубликовано: 19 янв. 2026
Источник: nvd
CVSS3: 6.4
EPSS Низкий

Описание

Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3, the application uses the Ruby eval() function to dynamically execute a string provided by the resource_handler.engine_name attribute in Alchemy::ResourcesHelper#resource_url_proxy. The vulnerability exists in app/helpers/alchemy/resources_helper.rb at line 28. The code explicitly bypasses security linting with # rubocop:disable Security/Eval, indicating that the use of a dangerous function was known but not properly mitigated. Since engine_name is sourced from module definitions that can be influenced by administrative configurations, it allows an authenticated attacker to escape the Ruby sandbox and execute arbitrary system commands on the host OS. Versions 7.4.12 and 8.0.3 fix the issue by replacing eval() with send().

EPSS

Процентиль: 5%
0.00022
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-95

Связанные уязвимости

CVSS3: 6.4
github
17 дней назад

AlchemyCMS: Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper

EPSS

Процентиль: 5%
0.00022
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-95