Stored Cross-Site Scripting in BookStack by AppThink
CVE-2026-84695
9.3CRITICAL
What is CVE-2026-84695?
BookStack prior to version 26.05.4 is susceptible to a stored cross-site scripting vulnerability through its drawing upload endpoint. This vulnerability occurs because it permits unvalidated base64 encoded content and lacks proper content inspection. Attackers with editor permissions can exploit this flaw by uploading SVG files containing malicious scripts. When accessed via the image gallery API, these scripts may execute in the browsers of administrators, compromising the security of the web application.
Affected Version(s)
bookstack 0 < 26.05.4
bookstack 26.05.4
