GHSA-8w7q-29mw-gf5cHighCVSS 7.7
Backstage: Improper validation of MkDocs theme configuration in TechDocs
🔗 CVE IDs covered (1)
📋 Description
Impact
When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4
Workarounds
- Configure TechDocs with
techdocs.generator.runIn: 'docker'instead of'local'to provide container isolation, though this does not fully mitigate the risk. - Restrict write access to repositories registered in the Backstage catalog to trusted users.
🎯 Affected products1
- npm/@backstage/plugin-techdocs-node:< 1.15.4
🔗 References (7)
- https://github.com/backstage/backstage/security/advisories/GHSA-8w7q-29mw-gf5c
- https://nvd.nist.gov/vuln/detail/CVE-2026-106509
- https://github.com/backstage/backstage/commit/02cd7cdbb18b687446277b5602adaee7f1d53cbb
- https://github.com/backstage/backstage/commit/a900a9953c8f7ad3ba1906d1d257725a9996cc9d
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-8w7q-29mw-gf5c