CI Report:
N/A
LinuxServer Changes:
Full Changelog: v25.12.2-ls241...v25.12.3-ls242
Remote Changes:
Security Release
BookStack v25.12.3 has been released.
This is a security release to address a vulnerability where form elements in page content could be used to trick more privileged users into making API requests.
We strongly advise that you update your instance if you allow untrusted users to create or edit pages.
Thanks to Joud Zakharia of zentrust partners GmbH for the discovery of this vulnerability, and thanks to Sven Faßbender of zentrust partners GmbH for their responsible disclosure and great communication of this issue.
Additional Update Notices
- Page Content - As of this release, most types of form content are now removed from page content on render. If you applied customizations which made use of in-page form content, you may now need to find alternative methods.
Full List of Changes
- Updated application PHP dependencies.
- Updated session-based API authentication to only be active for GET requests.
- Updated page content filtering to remove many common form elements & attributes.
- Updated translations with latest Crowdin changes. (#5997)