Impact
Prior to version 1.15.4, the @backstage/plugin-techdocs-node package contains an unsafe path resolution that permits arbitrary file read through mkdocs snippets. An authenticated user who is allowed to register documentation sources can include content from directories outside the intended documentation boundary, potentially exposing files accessible by the build process. This vulnerability is characterized by path traversal weaknesses (CWE‑59) and improper handling of file paths (CWE‑61). Successful exploitation would allow a privileged user to read sensitive files, compromising confidentiality and possibly exposing administrative configuration or source code.
Affected Systems
The affected systems are deployments of Backstage using the @backstage/plugin-techdocs-node package with any version older than 1.15.4. The broader Backstage framework (backstage:backstage) is implicated because the plugin is a core component. Users should verify the installed plugin version and ensure they are not running legacy releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. No EPSS data is available, so the exploitation likelihood cannot be quantified. The vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector is an authenticated user who has permissions to register or modify documentation sources; such a user could supply a snippet that points to a location outside the documentation tree, thereby reading internal files. Proper authentication boundaries and permission checks mitigate the exposure, but the flaw remains exploitable if these controls are relaxed.
OpenCVE Enrichment