Description
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.
Published: 2026-10-07
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability results from the @backstage/plugin‑techdocs‑node package not sufficiently verifying the configuration of Markdown extensions used in the TechDocs build process. A path‑traversal flaw allows a TechDocs build to read or write files outside the intended documentation boundary, potentially exposing backend‑host files or internal network resources to an attacker who can register or modify documentation sources. The weakness is classified as CWE‑22 and potentially CWE‑918 due to the way the configuration is processed.

Affected Systems

The affected components are Backstage’s @backstage/plugin‑techdocs‑node and the core Backstage platform. Versions prior to 1.14.6 and 1.15.4 are vulnerable, even when dependencies are present. The fix is included in Backstage 1.14.6 and later, and in 1.15.4 and later, provided that the project uses pymdown‑extensions 10.21.3 or later via mkdocs‑techdocs‑core 1.7.0 or newer.

Risk and Exploitability

With a CVSS base score of 7.7, the vulnerability is considered high severity. The EPSS score is currently unavailable, and the issue is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation yet. Attack requires an authenticated user with the ability to add or edit documentation sources, a privilege that may not be universally granted but could exist in many developer portal deployments. The risk is moderate to high, especially if the portal is exposed to untrusted or external developers. Monitoring for unusual build activity and tightening source‑configuration permissions can help mitigate exposure.

Generated by OpenCVE AI on October 7, 2026 at 17:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Backstage to version 1.14.6 or later, or to 1.15.4 or later, to include the fixed library versions.
  • Ensure your TechDocs configuration uses mkdocs‑techdocs‑core 1.7.0 or newer, which brings in pymdown‑extensions 10.21.3 or later, providing the proper validation for Markdown extensions.
  • Review and restrict the permissions for user accounts that can register or modify documentation sources, limiting who can influence the TechDocs build process.

Generated by OpenCVE AI on October 7, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f7v3-xhm6-w245 Backstage has improper input validation in TechDocs Markdown extension configuration
History

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.
Title Backstage: Improper input validation in TechDocs Markdown extension configuration
Weaknesses CWE-22
CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T17:47:16.631Z

Reserved: 2026-10-06T20:31:59.017Z

Link: CVE-2026-106557

cve-icon Vulnrichment

Updated: 2026-10-07T17:47:10.888Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:16:50.900

Modified: 2026-10-07T18:17:16.983

Link: CVE-2026-106557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:00:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-918

    Server-Side Request Forgery (SSRF)