BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.
https://www.vulncheck.com/advisories/bookstack-before-26.05.4-stored-xss-via-drawing-upload
https://www.bookstackapp.com/blog/bookstack-release-v26-05-4/
https://github.com/BookStackApp/BookStack/releases/tag/v26.05.4
https://github.com/BookStackApp/BookStack/commit/ac0348a79f3ddd004ca87703948cb9c7d19a420a
https://github.com/BookStackApp/BookStack/blob/v26.05.3/app/Uploads/ImageService.php
Published: 2026-09-02
Updated: 2026-09-02
Base Score: 8.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N
Severity: High
Base Score: 8.7
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Severity: High
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Severity: Critical
EPSS: 0.00255