CVE-2026-84695

critical

Description

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.

References

https://www.vulncheck.com/advisories/bookstack-before-26.05.4-stored-xss-via-drawing-upload

https://www.bookstackapp.com/blog/bookstack-release-v26-05-4/

https://github.com/BookStackApp/BookStack/releases/tag/v26.05.4

https://github.com/BookStackApp/BookStack/commit/ac0348a79f3ddd004ca87703948cb9c7d19a420a

https://github.com/BookStackApp/BookStack/blob/v26.05.3/app/Uploads/ImageService.php

https://github.com/BookStackApp/BookStack

Details

Source: Mitre, NVD

Published: 2026-09-02

Updated: 2026-09-02

Risk Information

CVSS v2

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 8.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Severity: High

CVSS v4

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Severity: Critical

EPSS

EPSS: 0.00255