GHSA-8w7q-29mw-gf5cHighCVSS 7.7

Backstage: Improper validation of MkDocs theme configuration in TechDocs

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process.

Patches

Patched in @backstage/plugin-techdocs-node version 1.15.4

Workarounds

  • Configure TechDocs with techdocs.generator.runIn: 'docker' instead of 'local' to provide container isolation, though this does not fully mitigate the risk.
  • Restrict write access to repositories registered in the Backstage catalog to trusted users.

🎯 Affected products1

  • npm/@backstage/plugin-techdocs-node:< 1.15.4

🔗 References (7)