Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w669-jj7h-88m9 | @backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 19 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation backstage |
|
| CPEs | cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linuxfoundation
Linuxfoundation backstage |
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Backstage
Backstage backstage |
|
| Vendors & Products |
Backstage
Backstage backstage |
Mon, 02 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 31 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 30 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vulnerability in the TechDocs local generator allows attackers to read arbitrary files from the host filesystem when Backstage is configured with `techdocs.generator.runIn: local`. When processing documentation from untrusted sources, symlinks within the docs directory are followed by MkDocs during the build process. File contents are embedded into generated HTML and exposed to users who can view the documentation. This vulnerability is fixed in` @backstage/plugin-techdocs-node` versions 1.13.11 and 1.14.1. Some workarounds are available. Switch to `runIn: docker` in `app-config.yaml` and/or restrict write access to TechDocs source repositories to trusted users only. | |
| Title | @backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-02T16:29:27.963Z
Reserved: 2026-01-29T15:39:11.821Z
Link: CVE-2026-25152
Updated: 2026-02-02T16:25:13.990Z
Status : Analyzed
Published: 2026-01-30T22:15:56.190
Modified: 2026-02-19T15:37:56.570
Link: CVE-2026-25152
OpenCVE Enrichment
Updated: 2026-02-02T09:26:47Z
Github GHSA