CVE-2026-84695

CRITICAL CVSS 4.0: 9.3 EPSS 0.26%
Updated Sep 08, 2026
Bookstackapp
Parameter Value
CVSS 9.3 (CRITICAL)
Affected Versions before 26.05.4
Fixed In 26.05.4
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Bookstackapp
Public PoC No

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Bookstackapp Bookstack
cpe:2.3:a:bookstackapp:bookstack:*:*:*:*:*:*:*:*
26.05.4