GHSA-qmw3-745m-w99gHighCVSS 8.8

Backstage: Improper validation of TechDocs MkDocs configuration

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An attacker who can provide configuration to a TechDocs build may execute code in the generator runtime. Impact is greatest when documentation generation runs with backend credentials or host access.

Patches

Patched in @backstage/plugin-techdocs-node version 1.15.4.

Workarounds

Use external TechDocs generation in an isolated environment without sensitive credentials or host access. Restrict and review changes to documentation configuration before generation.

🎯 Affected products1

  • npm/@backstage/plugin-techdocs-node:< 1.15.4

🔗 References (9)