CVE-2026-84695
BookStack before 26.05.4 Stored XSS via Drawing Upload
CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
0th
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.
| CWE | CWE-79 |
| Vendor | bookstackapp |
| Product | bookstack |
| Published | Sep 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for bookstackapp bookstack
Be the first to know when new high vulnerabilities affecting bookstackapp bookstack are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
bookstackapp / bookstack
0 < 26.05.4
References
github.com: https://github.com/BookStackApp/BookStack github.com: https://github.com/BookStackApp/BookStack/commit/ac0348a79f3ddd004ca87703948cb9c7d19a420a github.com: https://github.com/BookStackApp/BookStack/blob/v26.05.3/app/Uploads/ImageService.php github.com: https://github.com/BookStackApp/BookStack/releases/tag/v26.05.4 bookstackapp.com: https://www.bookstackapp.com/blog/bookstack-release-v26-05-4/ vulncheck.com: https://www.vulncheck.com/advisories/bookstack-before-26.05.4-stored-xss-via-drawing-upload
Credits
Emanuele Cervelli