Download Latest Version BookStack v26.03.2 source code.tar.gz (4.5 MB)
Email in envelope

Get an email when there's a new version of BookStack

Home / v26.03.2
Name Modified Size InfoDownloads / Week
Parent folder
BookStack v26.03.2 source code.tar.gz 2026-03-23 4.5 MB
BookStack v26.03.2 source code.zip 2026-03-23 5.7 MB
README.md 2026-03-23 1.3 kB
Totals: 3 Items   10.2 MB 10

Security Release

This is a security release to address a vulnerability where the registration form could be manipulated to gain access to additional roles.

Upgrade is very strongly advised if your instance has user registration enabled.

Thanks to Kwonyong Lee (LinkedIn) for responsibly reporting this issue. Also thanks to Boustani OSAMA (LinkedIn) for also reporting this before public announcement.

Full List of Changes

  • Updated user creation to only use validated input from registration.
  • Updated PHP package versions.
  • Updated translations with latest Crowdin changes. (#6064)
  • Updated PHP_CodeSniffer repository link. Thanks to @rodrigoprimo. (#6060)
  • Updated WYSIWYG editors to have consistent collapsible block double click behavior. (#6059)
Source: README.md, updated 2026-03-23