PatchSiren

bookstackapp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH bookstackapp CVE published 2026-08-29

CVE-2026-82450

CVE-2026-82450 is a remote code execution vulnerability in BookStack before version 26.05.4. The vulnerability exists in the portable ZIP import functionality and allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the [truncated]

MEDIUM BookStackApp CVE published 2026-04-03

CVE-2026-5484

A weakness has been identified in BookStackApp BookStack up to 26.03, specifically in the chapterToMarkdown function of the ExportFormatter.php file. This weakness can lead to improper access controls when the pages argument is manipulated. The vulnerability can be exploited remotely, and a public exploit is available. Upgrading to version 26.03.1 addresses this issue, which was patched with 8a59895ba0630 [truncated]