Impact
Backstage’s @backstage/plugin-techdocs-node package failed to properly validate the mapping‑style configuration supplied via the markdown_extensions setting. This flaw allows an attacker who can register or modify an SCM‑backed documentation source to inject YAML mapping objects that the MkDocs generator will deserialize and instantiate as Python objects. The result is that arbitrary code can be executed in the context of the backend process. Because the generator runs with backend credentials, filesystem privileges, and internal network access, the impact can extend to the entire system and internal services.
Affected Systems
Vendors affected are Backstage and the Backstage plugin-techdocs‑node. Versions impacted are all releases running before Backstage 1.14.8, 1.15.6, or 2.0.1. The issue was addressed in those three releases and later. Users should verify that both the core Backstage package and the plugin are at least the fixed versions listed.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and while an EPSS score is not available, the lack of a KEV listing implies no public exploit is known. The attack requires authentication and the ability to influence a documentation source, suggesting an attack vector in environments where developers or integrators can submit or modify source content. If successful, the attacker can execute code with the privileges of the backend daemon.
OpenCVE Enrichment