CVE-2026-23885 | AlchemyCMS alchemy_cms up to 7.4.11/8.0.2 resources_helper.rb eval eval injection (GHSA-2762-657x-v979 / EUVD-2026-3281)
A vulnerability was found in AlchemyCMS alchemy_cms up to 7.4.11/8.0.2. It has been classified as problematic. Affected is the function eval of the file app/helpers/alchemy/resources_helper.rb. This manipulation causes improper neutralization of directives in dynamically evaluated code.
This vulnerability is tracked as CVE-2026-23885. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.