Description
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Potential file exposure to authenticated users
Action: Immediate Patch
AI Analysis

Impact

The vulnerability originates from the @backstage/plugin-techdocs-node package, where the local TechDocs publisher can resolve filesystem references outside the intended documentation tree. The primary impact is that authenticated users of the portal can read host files that should otherwise be inaccessible, providing a local path‑traversal or local file inclusion effect (CWE‑22 and CWE‑59). The issue is limited to the local publishing mode (techdocs.publisher.type: 'local') and requires that the attacker already has valid authentication to the Backstage instance, as the exposure occurs through the documentation serving endpoint.

Affected Systems

The affected products are Backstage – the open framework for building developer portals – and its @backstage/plugin-techdocs-node component. Versions older than 1.15.4 for Backstage or the plugin are vulnerable. The vulnerability was fixed in Backstage release 1.15.4, which includes the updated plugin. The change affects the local TechDocs publisher configured with techdocs.publisher.type set to 'local'.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation in the wild is uncertain. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that an attacker be authenticated to the Backstage instance and that the local publisher is enabled – the flaw does not allow unauthenticated or remote code execution. The potential impact is the disclosure of host files to authenticated users, which could reveal sensitive configuration or code. Because the attack surface is limited to authenticated users and local publisher configuration, the overall risk is moderate, but applying the patch in version 1.15.4 or later is recommended to eliminate the path‑traversal flaw.

Generated by OpenCVE AI on October 7, 2026 at 01:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Backstage and the @backstage/plugin-techdocs-node package to version 1.15.4 or later, which contains the fix for this issue.
  • If the local publisher is required, enforce strict access controls so that only trusted staff can authenticate to the documentation endpoint, or disable the local publisher and use a cloud‑based publisher instead.
  • Validate that the configuration file (techdocs.publisher.type) is not set to 'local' for public or untrusted instances; apply network segmentation or firewall rules to limit exposure of the local file system to the Backstage process.

Generated by OpenCVE AI on October 7, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4.
Title Backstage: Potential file exposure through local TechDocs publisher
Weaknesses CWE-22
CWE-59
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T21:47:35.516Z

Reserved: 2026-10-06T18:46:47.767Z

Link: CVE-2026-106508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T22:17:06.310

Modified: 2026-10-06T22:17:06.310

Link: CVE-2026-106508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')