Description
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can register or influence an SCM-backed documentation source may bypass TechDocs sanitization and cause Python objects to be imported and instantiated in the generator runtime, leading to arbitrary code execution. Earlier fixes in versions 1.14.6 and 1.15.4 did not fully address the supported mapping representation of markdown_extensions. Impact is greatest when documentation generation runs with backend credentials, filesystem access, or internal network access. This issue is fixed in versions 1.14.8, 1.15.6, and 2.0.1.
Published: 2026-10-07
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Patch ASAP
AI Analysis

Impact

Backstage’s @backstage/plugin-techdocs-node package failed to properly validate the mapping‑style configuration supplied via the markdown_extensions setting. This flaw allows an attacker who can register or modify an SCM‑backed documentation source to inject YAML mapping objects that the MkDocs generator will deserialize and instantiate as Python objects. The result is that arbitrary code can be executed in the context of the backend process. Because the generator runs with backend credentials, filesystem privileges, and internal network access, the impact can extend to the entire system and internal services.

Affected Systems

Vendors affected are Backstage and the Backstage plugin-techdocs‑node. Versions impacted are all releases running before Backstage 1.14.8, 1.15.6, or 2.0.1. The issue was addressed in those three releases and later. Users should verify that both the core Backstage package and the plugin are at least the fixed versions listed.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and while an EPSS score is not available, the lack of a KEV listing implies no public exploit is known. The attack requires authentication and the ability to influence a documentation source, suggesting an attack vector in environments where developers or integrators can submit or modify source content. If successful, the attacker can execute code with the privileges of the backend daemon.

Generated by OpenCVE AI on October 7, 2026 at 16:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Backstage and the @backstage/plugin-techdocs-node package to version 1.14.8, 1.15.6, or 2.0.1 or newer.
  • Ensure that only trusted users or processes can register or modify SCM‑backed documentation sources, and reinforce role‑based access controls to restrict configuration changes.
  • Validate and sanitize any external Markdown extensions before passing them to the MkDocs generator, such as by whitelisting allowed extension names or using strict parsing options, to add an extra layer of protection.

Generated by OpenCVE AI on October 7, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can register or influence an SCM-backed documentation source may bypass TechDocs sanitization and cause Python objects to be imported and instantiated in the generator runtime, leading to arbitrary code execution. Earlier fixes in versions 1.14.6 and 1.15.4 did not fully address the supported mapping representation of markdown_extensions. Impact is greatest when documentation generation runs with backend credentials, filesystem access, or internal network access. This issue is fixed in versions 1.14.8, 1.15.6, and 2.0.1.
Title Backstage: Improper validation of TechDocs MkDocs configuration
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T14:45:25.679Z

Reserved: 2026-10-06T20:31:59.017Z

Link: CVE-2026-106558

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T15:17:15.713

Modified: 2026-10-07T15:52:18.453

Link: CVE-2026-106558

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T16:45:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data