GHSA-f7v3-xhm6-w245HighCVSS 7.7
Backstage has improper input validation in TechDocs Markdown extension configuration
🔗 CVE IDs covered (1)
📋 Description
Impact
An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4.
Adopters must also use pymdown-extensions version 10.21.3 or newer, normally through mkdocs-techdocs-core version 1.7.0 or newer. @backstage/plugin-techdocs-node does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized.
Workarounds
- Generate TechDocs only from trusted repositories with reviewed MkDocs configuration.
- Use isolated build environments with restricted filesystem access and network egress.
- Prefer externally generated TechDocs with appropriately sandboxed CI.
🎯 Affected products1
- npm/@backstage/plugin-techdocs-node:< 1.15.4
🔗 References (6)
- https://github.com/backstage/backstage/security/advisories/GHSA-f7v3-xhm6-w245
- https://github.com/backstage/backstage/commit/017ace52d9b327ededc6704cf17799c875ae0f29
- https://github.com/backstage/backstage/commit/2d9de4ca117a529de4b6ed7dfb7aa507ca7b3f91
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-f7v3-xhm6-w245