Impact
AlchemyCMS releases older than 7.4.16 and any 8.x before 8.3.6 permit unauthenticated access to GET /api/nodes. The endpoint returns all navigation nodes, revealing page names, URL paths, and internal URLs for every site and language. This enables attackers to uncover sensitive site structure data, supporting further reconnaissance.
Affected Systems
The flaw affects AlchemyCMS, a Ruby on Rails based CMS. Systems running any version before 7.4.16 or any 8.x before 8.3.6 are impacted. Upstream patches are available in releases 7.4.16 and 8.3.6.
Risk and Exploitability
CVSS base score of 6.9 indicates medium severity. EPSS is not published, so the probability of exploitation is unclear, but the lack of authentication makes the attack vector trivial once the API is exposed. The flaw is not listed in CISA KEV, suggesting no known active exploitation but still worthy of prompt remediation.
OpenCVE Enrichment