BookStack Security Release v26.05.5

BookStack v26.05.5 has been released.

This is a security release which addresses a vulnerability related to social login accounts, to prevent accounts from different services being potentially mis-matched.

Upgrading is strongly advised if the instance has ever used more than one third-party/social login option (including previously used options which are no longer active).

Thanks to Google and Ada Logics for the discovery and responsible disclosure of this issue.

Full List of Changes

  • Updated social logins to scope social account queries to social system.
  • Updated PHP package versions.

For More Information

You can find update instructions here.
If you have any questions or comments about this advisory:


Header Image Credits: Photo by Dietmar Rabich (cc-by-sa-4) - Image Modified