Impact
The vulnerability originates from the @backstage/plugin-techdocs-node package, where the local TechDocs publisher can resolve filesystem references outside the intended documentation tree. The primary impact is that authenticated users of the portal can read host files that should otherwise be inaccessible, providing a local path‑traversal or local file inclusion effect (CWE‑22 and CWE‑59). The issue is limited to the local publishing mode (techdocs.publisher.type: 'local') and requires that the attacker already has valid authentication to the Backstage instance, as the exposure occurs through the documentation serving endpoint.
Affected Systems
The affected products are Backstage – the open framework for building developer portals – and its @backstage/plugin-techdocs-node component. Versions older than 1.15.4 for Backstage or the plugin are vulnerable. The vulnerability was fixed in Backstage release 1.15.4, which includes the updated plugin. The change affects the local TechDocs publisher configured with techdocs.publisher.type set to 'local'.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation in the wild is uncertain. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that an attacker be authenticated to the Backstage instance and that the local publisher is enabled – the flaw does not allow unauthenticated or remote code execution. The potential impact is the disclosure of host files to authenticated users, which could reveal sensitive configuration or code. Because the attack surface is limited to authenticated users and local publisher configuration, the overall risk is moderate, but applying the patch in version 1.15.4 or later is recommended to eliminate the path‑traversal flaw.
OpenCVE Enrichment