CRITICAL 9.3 NVD

CVE-2026-84695

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed through the image gallery API without content-type validation or CSP headers.

References

Published: 2026-09-02 · Source: NVD · Feed updated: 2026-09-02
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-02 via NVD.

Risk Timeline

CVE Disclosed2026-09-02 · -1 days ago

Remediation Resources

vulnfeed aggregates 11552 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.