GHSA-f7v3-xhm6-w245HighCVSS 7.7

Backstage has improper input validation in TechDocs Markdown extension configuration

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources.

Patches

Patched in @backstage/plugin-techdocs-node version 1.15.4.

Adopters must also use pymdown-extensions version 10.21.3 or newer, normally through mkdocs-techdocs-core version 1.7.0 or newer. @backstage/plugin-techdocs-node does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized.

Workarounds

  • Generate TechDocs only from trusted repositories with reviewed MkDocs configuration.
  • Use isolated build environments with restricted filesystem access and network egress.
  • Prefer externally generated TechDocs with appropriately sandboxed CI.

🎯 Affected products1

  • npm/@backstage/plugin-techdocs-node:< 1.15.4

🔗 References (6)