CVE-2026-106455: Backstage: Improper validation of MkDocs plugin configuration in TechDocs
Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a documentation build to retrieve and publish data from network locations reachable by the build environment. Exposure depends on deployment topology, build mode, and target endpoint protections. Modern cloud metadata services that require tokens or special headers are not directly accessible through the affected behavior. This issue is fixed in @backstage/plugin-techdocs-node versions 1.14.7 and 1.15.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.14.7 - Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.5
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and able to control a TechDocs source repository. The impact also depends on whether the TechDocs build environment can reach the attacker-selected network location.
Are cloud instance metadata services exposed?
Modern cloud metadata services that require tokens or special headers are not directly accessible through this behavior. Other network locations reachable from the documentation build environment may still be retrievable and published.
Which deployments are most exposed?
Exposure depends on deployment topology, TechDocs build mode, and protections at the target endpoint. Environments where documentation builds have broad access to internal network services have greater potential exposure.
What versions contain the fix?
The issue is fixed in @backstage/plugin-techdocs-node versions 1.14.7 and 1.15.5.