Impact
BookStack before version 26.05.4 holds a stored cross‑site scripting flaw in the drawing upload endpoint. The flaw accepts base64 encoded content from editor‑level users and writes it to storage without inspecting its content or validating its type. SVG files containing embedded JavaScript can therefore be uploaded and later served from the image gallery API, where they execute in the browsers of users with administrator privileges. The vulnerability is a classic example of unvalidated input that leads to user‑controlled script execution, categorized as CWE‑79.
Affected Systems
The affected product is BookStack, managed by the bookstackapp vendor. All releases prior to the 26.05.4 tag are vulnerable.
Risk and Exploitability
The weakness has a CVSS score of 9.3, marking it as critical. EPSS is not available, but the lack of detection information combined with an exploit strategy that only requires editor permissions – a common role – suggests a high likelihood of exploitation in environments where administrators are present. The vulnerability is not listed in the CISA KEV catalog, but its severity and the ease of payload upload make it a serious security concern.
OpenCVE Enrichment