GHSA-qmw3-745m-w99gHighCVSS 8.8
Backstage: Improper validation of TechDocs MkDocs configuration
🔗 CVE IDs covered (1)
📋 Description
Impact
An attacker who can provide configuration to a TechDocs build may execute code in the generator runtime. Impact is greatest when documentation generation runs with backend credentials or host access.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4.
Workarounds
Use external TechDocs generation in an isolated environment without sensitive credentials or host access. Restrict and review changes to documentation configuration before generation.
🎯 Affected products1
- npm/@backstage/plugin-techdocs-node:< 1.15.4
🔗 References (9)
- https://github.com/backstage/backstage/security/advisories/GHSA-qmw3-745m-w99g
- https://nvd.nist.gov/vuln/detail/CVE-2026-106558
- https://github.com/backstage/backstage/commit/32723a0fe4e12ed80535fc65d5331765c55aa91b
- https://github.com/backstage/backstage/commit/944edb51c8524d3664b18f2d57ba101b1c93b709
- https://github.com/backstage/backstage/commit/f18e9abcc6051491862b15e4fc60e69f8d52310c
- https://github.com/backstage/backstage/releases/tag/v1.50.7
- https://github.com/backstage/backstage/releases/tag/v1.54.9
- https://github.com/backstage/backstage/releases/tag/v1.55.2
- https://github.com/advisories/GHSA-qmw3-745m-w99g