Impact
Backstage’s TechDocs plugin validates the mkdocs.yml file provided by an authenticated user who registers or changes a TechDocs source. The plugin fails to sanitize unsafe Python YAML tags, markdown extensions, theme options, and extra template values, allowing malicious content to reach the documentation generator. Execution of this content occurs inside the TechDocs build or backend container, potentially giving the attacker read or write access to the container’s file system, credentials stored there and any network connections available to that container. The vulnerability remains limited to the resources the TechDocs backend or build container can access; it does not grant direct access to the overall Backstage instance or underlying host.
Affected Systems
The issue affects installations of Backstage prior to version 1.14.6 as well as versions 1.15.0 through 1.15.4. The affected component is the @backstage/plugin-techdocs-node package, which processes user‑supplied mkdocs.yml files for documentation generation.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attack requires an authenticated user with privilege to register or modify a TechDocs source; once authenticated, the attacker can supply a crafted mkdocs.yml that is executed during the generation process, leading to remote code execution within the build environment. Because the impact is confined to the backend build container, the risk is substantial in that environment but does not automatically translate to host compromise.
OpenCVE Enrichment