Impact
The vulnerability results from the @backstage/plugin‑techdocs‑node package not sufficiently verifying the configuration of Markdown extensions used in the TechDocs build process. A path‑traversal flaw allows a TechDocs build to read or write files outside the intended documentation boundary, potentially exposing backend‑host files or internal network resources to an attacker who can register or modify documentation sources. The weakness is classified as CWE‑22 and potentially CWE‑918 due to the way the configuration is processed.
Affected Systems
The affected components are Backstage’s @backstage/plugin‑techdocs‑node and the core Backstage platform. Versions prior to 1.14.6 and 1.15.4 are vulnerable, even when dependencies are present. The fix is included in Backstage 1.14.6 and later, and in 1.15.4 and later, provided that the project uses pymdown‑extensions 10.21.3 or later via mkdocs‑techdocs‑core 1.7.0 or newer.
Risk and Exploitability
With a CVSS base score of 7.7, the vulnerability is considered high severity. The EPSS score is currently unavailable, and the issue is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation yet. Attack requires an authenticated user with the ability to add or edit documentation sources, a privilege that may not be universally granted but could exist in many developer portal deployments. The risk is moderate to high, especially if the portal is exposed to untrusted or external developers. Monitoring for unusual build activity and tightening source‑configuration permissions can help mitigate exposure.
OpenCVE Enrichment
Github GHSA