BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers. | |
| Title | BookStack before 26.05.4 Stored XSS via Drawing Upload | |
| First Time appeared |
Bookstackapp
Bookstackapp bookstack |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:bookstackapp:bookstack:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bookstackapp
Bookstackapp bookstack |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T00:37:51.655Z
Reserved: 2026-09-01T23:24:15.911Z
Link: CVE-2026-84695
No data.
Status : Received
Published: 2026-09-02T01:17:24.400
Modified: 2026-09-02T01:17:24.400
Link: CVE-2026-84695
No data.
OpenCVE Enrichment
Updated: 2026-09-02T03:30:06Z
Weaknesses