CVE-2026-57579: Alchemy: Unauthenticated nested page API leaks restricted & unpublished content

Published Sep 14, 2026
·
Updated

Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the unauthenticated GET /api/pages/nested endpoint implemented by Api::PagesController#nested in app/controllers/alchemy/api/pagescontroller.rb returns an unfiltered page tree because it performs no authorization and does not scope descendants by the caller's ability. Anonymous callers can retrieve restricted and unpublished page metadata that the sibling show action denies. When elements=true is supplied, PageTreeSerializer also returns element and ingredient content from restricted pages because PageTreePreloader and the serializer do not apply an ability check to those records. This issue is fixed in versions 7.4.15, 8.0.15, 8.1.14, and 8.2.6.

Affected Software

1 affected component
Alchemy Alchemy<7.4.15, <8.0.15, <8.1.14, <8.2.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Alchemy to a version that resolves this vulnerability.

    Fixed in 7.4.15
  2. Upgrade

    Upgrade Alchemy to a version that resolves this vulnerability.

    Fixed in 8.0.15
  3. Upgrade

    Upgrade Alchemy to a version that resolves this vulnerability.

    Fixed in 8.1.14
  4. Upgrade

    Upgrade Alchemy to a version that resolves this vulnerability.

    Fixed in 8.2.6

Event History

Sep 14, 2026
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can access the exposed content?

Any anonymous network caller can query the affected GET /api/pages/nested endpoint. No authentication, privileges, or user interaction are required.

2

What information can be disclosed?

The endpoint can return metadata for restricted and unpublished pages. Supplying elements=true can additionally expose element and ingredient content from restricted pages.

3

How can I determine whether an instance is vulnerable?

Affected instances are those running Alchemy earlier than 7.4.15, 8.0.15, 8.1.14, or 8.2.6. The vulnerable behavior is present when an unauthenticated request to GET /api/pages/nested can return restricted or unpublished pages.

4

What remediation is available?

Upgrade to Alchemy 7.4.15, 8.0.15, 8.1.14, or 8.2.6, as appropriate for the deployed release line.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203