GHSA-4488-j8vj-vqqvHighCVSS 7.7

Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built.

Patches

Patched in @backstage/plugin-techdocs-node, version 1.15.4.

Workarounds

If you cannot upgrade immediately:

  • Switch to techdocs.builder: external to isolate TechDocs builds in a container.
  • Restrict who can register catalog entities with TechDocs annotations.
  • Audit existing catalog entities for suspicious markdown_extensions values in their mkdocs.yml files.

🎯 Affected products1

  • npm/@backstage/plugin-techdocs-node:< 1.15.4

🔗 References (7)