{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/bookstack/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bookstackapp:bookstack:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-82450"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BookStack (\u003c 26.05.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["BookStack"],"content_html":"\u003cp\u003eBookStack versions prior to 26.05.4 are susceptible to a remote code execution vulnerability located in the portable ZIP import feature. The flaw arises from insufficient validation of file extensions within ZIP archives. An authenticated user possessing 'Import Content' and 'Create Books' permissions can upload a ZIP archive containing a PHP polyglot file disguised as a book cover image. The application extracts the malicious file and stores it within the public web root directory. Because the system does not properly sanitize or verify the contents of the ZIP, the attacker can subsequently trigger the execution of the stored PHP script by making a direct, unauthenticated HTTP request to the location of the uploaded file. This vulnerability poses a significant risk as it allows for arbitrary code execution on the underlying server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated attacker to achieve arbitrary remote code execution on the server hosting the BookStack application. This can lead to full system compromise, data exfiltration, or the deployment of persistent backdoors within the organization's infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the BookStack instance to version 26.05.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview the permissions of accounts with 'Import Content' and 'Create Books' access to ensure the principle of least privilege is maintained.\u003c/li\u003e\n\u003cli\u003eAudit the web root directory for unauthorized .php files that do not correspond to the legitimate application structure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T15:39:54Z","date_published":"2026-08-29T15:39:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-bookstack-rce/","summary":"BookStack before version 26.05.4 is vulnerable to remote code execution due to improper validation of files within the portable ZIP import functionality.","title":"Remote Code Execution in BookStack via ZIP Import","url":"https://feed.craftedsignal.io/briefs/2026-08-bookstack-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - BookStack","version":"https://jsonfeed.org/version/1.1"}