PT-2026-84574 · Bookstack · Bookstack

·

CVE-2026-84695

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions BookStack versions prior to 26.05.4
Description A stored cross-site scripting issue exists in the drawing upload endpoint. The system accepts unvalidated base64 content and stores it without performing content inspection. Users with editor permissions can upload SVG files containing malicious scripts. These scripts execute in the browser of an administrator when the files are accessed through the image gallery API, which lacks content-type validation and Content Security Policy (CSP) headers—security layers that help detect and mitigate certain types of attacks, including XSS.
Recommendations Update BookStack to version 26.05.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84695

Affected Products

Bookstack