BookStack Security Release v25.11.6
Dan Brown posted on the 9th of December 2025
BookStack v25.11.6 has been released.
This is a security release to address a vulnerability in our dependencies related to XML handling, which could allow users to replay SAML authentication requests with specially crafted & manipulated requests.
It’s strongly advised to update if you’re using SAML authentication for BookStack.
Full List of Changes
- Updated application PHP dependencies.
For More Information
If you have any questions or comments about this advisory:
- Open an issue in the BookStack GitHub repository.
- Ask on the BookStack Discord chat.
- Follow the BookStack security policy to contact someone privately.
Header Image Credits: Photo by Dietmar Rabich (CC-BY-SA 4.0) - Image Modified