Skip to content

BookStack

Productivity & Wikis

A platform to create documentation/wiki content built with PHP & Laravel

PHP Latest v26.05.2 · 24d ago Security brief →

Features

  • Opinionated documentation platform with simple out‑of‑the‑box experience
  • Intuitive UI requiring only basic word‑processing skills for content creation
  • Provides advanced power features without compromising core simplicity

Recent releases

View all 17 releases →
Upgrade now
v26.05.2 Security relevant
Auth RBAC

URL filtering + permission security

Upgrade now
v26.05.1 Security relevant
Auth RCE / SSRF

Attachment leak + file protocol abuse

Config change
v26.05 New feature
Auth RBAC

Page preview + Tag API + PDF fonts + MFA

Upgrade now
v26.03.5 Security relevant
Auth

MFA rate limiting

v26.03.4 Security relevant
Security fixes
  • Improved attachment-related permission checks
  • URL validation for webhooks to prevent escaping workarounds
Full changelog

Security Release

This is a security release to improve attachment related permission checks, and URL validation for webhooks.

Upgrade is advised if you allow untrusted users to delete attachments, or if untrusted users have permission to create webhooks on instances which make use of the ALLOWED_SSR_HOSTS BookStack env file option.

Thanks to 404_pkj (GitHub) and naruhodoowl (GitHub) for responsibly reporting these issues.

Full List of Changes

  • Updated PHP package versions.
  • Updated attachment actions to align page access check.
  • Updated URL validation in webhooks to help prevent escaping workarounds.
  • Fixed issue where exact search term negation would lead to no results. (#6121)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
18,911
Forks
2,403
Languages
PHP TypeScript Blade

Community & Support

Beta — feedback welcome: [email protected]