Description
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Arbitrary File Read
Action: Immediate Patch
AI Analysis

Impact

Prior to version 1.15.4, the @backstage/plugin-techdocs-node package contains an unsafe path resolution that permits arbitrary file read through mkdocs snippets. An authenticated user who is allowed to register documentation sources can include content from directories outside the intended documentation boundary, potentially exposing files accessible by the build process. This vulnerability is characterized by path traversal weaknesses (CWE‑59) and improper handling of file paths (CWE‑61). Successful exploitation would allow a privileged user to read sensitive files, compromising confidentiality and possibly exposing administrative configuration or source code.

Affected Systems

The affected systems are deployments of Backstage using the @backstage/plugin-techdocs-node package with any version older than 1.15.4. The broader Backstage framework (backstage:backstage) is implicated because the plugin is a core component. Users should verify the installed plugin version and ensure they are not running legacy releases.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact. No EPSS data is available, so the exploitation likelihood cannot be quantified. The vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector is an authenticated user who has permissions to register or modify documentation sources; such a user could supply a snippet that points to a location outside the documentation tree, thereby reading internal files. Proper authentication boundaries and permission checks mitigate the exposure, but the flaw remains exploitable if these controls are relaxed.

Generated by OpenCVE AI on October 7, 2026 at 01:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update @backstage/plugin-techdocs-node to version 1.15.4 or later
  • Restrict the permission set so that only trusted administrators can register documentation sources
  • Disable or tightly control mkdocs snippet inclusion and enforce safe path resolution for any remaining custom snippets

Generated by OpenCVE AI on October 7, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.
Title Backstage: TechDocs arbitrary file read via mkdocs snippets
Weaknesses CWE-59
CWE-61
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T21:46:08.014Z

Reserved: 2026-10-06T18:46:47.766Z

Link: CVE-2026-106507

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T22:17:06.153

Modified: 2026-10-06T22:17:06.153

Link: CVE-2026-106507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:15:09Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')

  • CWE-61

    UNIX Symbolic Link (Symlink) Following