<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update BookStack?</title>
    <link>https://bumplog.org/apps/bookstack/</link>
    <description>Update-safety verdicts for BookStack (BookStackApp/BookStack), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/bookstack/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>BookStack v26.05.2 — Update with care</title>
      <link>https://bumplog.org/apps/bookstack/</link>
      <guid isPermaLink="false">bumplog:app:bookstack:v26.05.2:caution</guid>
      <pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate>
      <description>Update with care. No breaking changes, schema migrations, or manual upgrade steps are mentioned, so the update itself is low-risk. However, the maintainers explicitly advise upgrading for any instance with public access or untrusted editors, and the behavioral changes to URL/srcset filtering and comment permission enforcement are security-relevant and worth verifying against any custom content policies before deploying. What changed: v26.05.2 is a security patch addressing edge-case vulnerabilities in URL filtering, redirect handling, and comment permission checks. Content allow-filtering was extended to cover protocols inside srcset attributes, and URL filtering was consolidated into a more robust centralized utility. A missing visibility-permission check on comment deletion was also corrected. The release additionally adds Serbian as a selectable language and refreshes PHP dependencies and translations. Source release: https://github.com/BookStackApp/BookStack/releases/tag/v26.05.2</description>
    </item>
  </channel>
</rss>
