CVE-2026-106505: Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.14.6 - Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who can commit changes to a repository that uses TechDocs can exploit it. The issue is triggered when TechDocs generates documentation from that repository.
What level of access does successful exploitation provide?
Successful exploitation can result in arbitrary code execution on the TechDocs backend host during documentation generation. The reported impact includes high confidentiality impact and low integrity and availability impact.
Which package versions are fixed?
The issue is fixed in @backstage/plugin-techdocs-node versions 1.14.6 and 1.15.4. Versions prior to those releases are affected.