GHSA-p75x-jh7p-ppcxHighCVSS 7.7

Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation.

Patches

Patched in@backstage/plugin-techdocs-node version 1.15.4

Workarounds

If you cannot upgrade immediately:

  • Use Docker mode with restricted access: Configure TechDocs with runIn: docker instead of runIn: local. This provides container isolation, though it does not fully mitigate the risk.
  • Limit repository write access to trusted parties, since exploitation requires the ability to commit files to a repository with TechDocs enabled.
  • Review incoming changes to MkDocs configuration files as part of your code review process.

🎯 Affected products1

  • npm/@backstage/plugin-techdocs-node:< 1.15.4

🔗 References (7)