CVE-2026-106556: Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configuration bypass in techdocs mkdocs.yml sanitization. Insufficient validation of MkDocs configuration during TechDocs generation could allow an authenticated user who can register or modify documentation sources to execute arbitrary commands in the build environment. Impact is limited to resources accessible to the TechDocs backend or build container. This issue is fixed in versions 1.14.6 and 1.15.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.14.6 - Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user must be able to register or modify documentation sources. Exploitation requires crafting MkDocs configuration that bypasses TechDocs sanitization during documentation generation.
What systems and data are at risk if exploitation succeeds?
The attacker can execute arbitrary commands in the TechDocs build environment. Impact is limited to resources accessible to the TechDocs backend or its build container.
What version should be deployed to remediate the issue?
Upgrade @backstage/plugin-techdocs-node to a fixed version: 1.14.6 or 1.15.4.