GHSA-p75x-jh7p-ppcxHighCVSS 7.7
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
🔗 CVE IDs covered (1)
📋 Description
Impact
Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation.
Patches
Patched in@backstage/plugin-techdocs-node version 1.15.4
Workarounds
If you cannot upgrade immediately:
- Use Docker mode with restricted access: Configure TechDocs with
runIn: dockerinstead ofrunIn: local. This provides container isolation, though it does not fully mitigate the risk. - Limit repository write access to trusted parties, since exploitation requires the ability to commit files to a repository with TechDocs enabled.
- Review incoming changes to MkDocs configuration files as part of your code review process.
🎯 Affected products1
- npm/@backstage/plugin-techdocs-node:< 1.15.4
🔗 References (7)
- https://github.com/backstage/backstage/security/advisories/GHSA-p75x-jh7p-ppcx
- https://nvd.nist.gov/vuln/detail/CVE-2026-106505
- https://github.com/backstage/backstage/commit/a7d995f11a5d27f0efbdbe8bb6c21b06988c79c9
- https://github.com/backstage/backstage/commit/ef92d3d2b76046205c580e7152956514c15640db
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-p75x-jh7p-ppcx