Impact
Alchemy is an open‑source CMS written in Ruby on Rails. Prior to versions 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the GET /api/pages/nested endpoint in Api::PagesController#nested can be accessed without authentication and returns an unfiltered page tree. Because it performs no authorization and does not scope descendants by the caller’s ability, an attacker can retrieve metadata for pages that are restricted or unpublished. When the query parameter elements=true is supplied, the serializer also returns the content of elements and ingredients from those restricted pages, leaking actual content. This allows an intruder to learn the site structure, the existence of unpublished material, and potentially sensitive page data, all without needing credentials. Such leakage can aid further attacks or serve as a knowledge vector for social engineering or data theft, constituting a confidentiality vulnerability.
Affected Systems
All installations of AlchemyCMS running any version earlier than 7.4.15, 8.0.15, 8.1.14, or 8.2.6 are affected. The vulnerability lives in the Alchemy CMS code base in the api/pages_controller.rb file and its child serializers. There is no mention of specific host environments; any publicly accessible instance is susceptible.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low probability of exploitation. The CVSS score of 7.5 indicates a moderate risk level. The issue is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the wild yet. The likely attack vector is an unauthenticated HTTP GET request to /api/pages/nested, which requires no credentials and no special environment configuration.
OpenCVE Enrichment