top of page
perceptive_background_267k.jpg

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Creat…

Published:

29 August 2026 at 00:00:00

Alert date:

29 August 2026 at 17:02:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities

BookStack versions before 26.05.4 are affected by a remote code execution vulnerability in the portable ZIP import functionality. Authenticated users with Import Content and Create Books permissions can exploit this by uploading a PHP polyglot file disguised as a book cover image. The attack bypasses image extension validation by embedding a PHP file with a .php filename inside the ZIP archive. Once uploaded, the malicious file is stored in the public web root and can be executed by unauthenticated HTTP requests. This effectively allows privilege escalation from a limited authenticated user to full server-side code execution. The vulnerability has been patched in BookStack version 26.05.4. References include the official BookStack GitHub repository and a specific commit addressing the flaw.

Technical details

Mitigation steps:

Affected products:

BookStack before 26.05.4

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page