BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.

Project Subscriptions

Vendors Products
Bookstackapp Subscribe
Bookstack Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Description BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.
Title BookStack before 26.05.4 Stored XSS via Drawing Upload
First Time appeared Bookstackapp
Bookstackapp bookstack
Weaknesses CWE-79
CPEs cpe:2.3:a:bookstackapp:bookstack:*:*:*:*:*:*:*:*
Vendors & Products Bookstackapp
Bookstackapp bookstack
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-02T16:01:37.536Z

Reserved: 2026-09-01T23:24:15.911Z

Link: CVE-2026-84695

cve-icon Vulnrichment

Updated: 2026-09-02T13:42:26.907Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T01:17:24.400

Modified: 2026-09-08T20:18:59.270

Link: CVE-2026-84695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:30:04Z

Weaknesses