PT-2026-84574 · Bookstack · Bookstack
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
BookStack versions prior to 26.05.4
Description
A stored cross-site scripting issue exists in the drawing upload endpoint. The system accepts unvalidated base64 content and stores it without performing content inspection. Users with editor permissions can upload SVG files containing malicious scripts. These scripts execute in the browser of an administrator when the files are accessed through the image gallery API, which lacks content-type validation and Content Security Policy (CSP) headers—security layers that help detect and mitigate certain types of attacks, including XSS.
Recommendations
Update BookStack to version 26.05.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bookstack