Stored Cross-Site Scripting in BookStack by AppThink
CVE-2026-84695

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84695?

BookStack prior to version 26.05.4 is susceptible to a stored cross-site scripting vulnerability through its drawing upload endpoint. This vulnerability occurs because it permits unvalidated base64 encoded content and lacks proper content inspection. Attackers with editor permissions can exploit this flaw by uploading SVG files containing malicious scripts. When accessed via the image gallery API, these scripts may execute in the browsers of administrators, compromising the security of the web application.

Affected Version(s)

bookstack 0 < 26.05.4

bookstack 26.05.4

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emanuele Cervelli
.