Description
Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can register or modify a TechDocs source. Unsafe Python YAML tags, markdown_extensions names and configuration, theme options, and extra_templates values can reach the documentation generator and cause unintended code execution. The resulting impact is limited to the files, credentials, network access, and other resources available to the TechDocs backend or build container. This issue is fixed in versions 1.14.6 and 1.15.4.
Published: 2026-09-16
Score: 8.8 High
EPSS: 1.2% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Backstage’s TechDocs plugin validates the mkdocs.yml file provided by an authenticated user who registers or changes a TechDocs source. The plugin fails to sanitize unsafe Python YAML tags, markdown extensions, theme options, and extra template values, allowing malicious content to reach the documentation generator. Execution of this content occurs inside the TechDocs build or backend container, potentially giving the attacker read or write access to the container’s file system, credentials stored there and any network connections available to that container. The vulnerability remains limited to the resources the TechDocs backend or build container can access; it does not grant direct access to the overall Backstage instance or underlying host.

Affected Systems

The issue affects installations of Backstage prior to version 1.14.6 as well as versions 1.15.0 through 1.15.4. The affected component is the @backstage/plugin-techdocs-node package, which processes user‑supplied mkdocs.yml files for documentation generation.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attack requires an authenticated user with privilege to register or modify a TechDocs source; once authenticated, the attacker can supply a crafted mkdocs.yml that is executed during the generation process, leading to remote code execution within the build environment. Because the impact is confined to the backend build container, the risk is substantial in that environment but does not automatically translate to host compromise.

Generated by OpenCVE AI on September 18, 2026 at 02:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Backstage to version 1.14.6 or later, or to 1.15.4 or later, to apply the vendor’s fix for the yaml validation problem.
  • If an immediate upgrade is not feasible, isolate the TechDocs build process by disabling or sanitizing unsafe YAML tags, and restricting markdown_extensions, theme options, and extra_templates before the file is processed.
  • Ensure that the TechDocs backend or build containers run with the least privilege necessary, with restricted filesystem and network access, and monitor container logs for anomalous execution attempts.

Generated by OpenCVE AI on September 18, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Backstage
Backstage backstage
Vendors & Products Backstage
Backstage backstage

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can register or modify a TechDocs source. Unsafe Python YAML tags, markdown_extensions names and configuration, theme options, and extra_templates values can reach the documentation generator and cause unintended code execution. The resulting impact is limited to the files, credentials, network access, and other resources available to the TechDocs backend or build container. This issue is fixed in versions 1.14.6 and 1.15.4.
Title Backstage: Improper input validation in TechDocs MkDocs configuration
Weaknesses CWE-1336
CWE-20
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Backstage Backstage
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:46:46.830Z

Reserved: 2026-09-09T21:22:45.434Z

Link: CVE-2026-88064

cve-icon Vulnrichment

Updated: 2026-09-16T15:46:36.744Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:18:04.297

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-88064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine

  • CWE-20

    Improper Input Validation