PatchSiren

BookStackApp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM BookStackApp CVE published 2026-04-03

CVE-2026-5484

A weakness has been identified in BookStackApp BookStack up to 26.03, specifically in the chapterToMarkdown function of the ExportFormatter.php file. This weakness can lead to improper access controls when the pages argument is manipulated. The vulnerability can be exploited remotely, and a public exploit is available. Upgrading to version 26.03.1 addresses this issue, which was patched with 8a59895ba0630 [truncated]