BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unauthenticated requests.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 29 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unauthenticated requests. | |
| Title | BookStack before 26.05.4 Remote Code Execution via Book Cover | |
| First Time appeared |
Bookstackapp
Bookstackapp bookstack |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:bookstackapp:bookstack:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bookstackapp
Bookstackapp bookstack |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T13:47:53.312Z
Reserved: 2026-08-29T13:22:57.885Z
Link: CVE-2026-82450
No data.
Status : Received
Published: 2026-08-29T14:16:37.930
Modified: 2026-08-29T14:16:37.930
Link: CVE-2026-82450
No data.
OpenCVE Enrichment
Updated: 2026-08-29T16:00:03Z
Weaknesses