CVE-2026-106557: Backstage: Improper input validation in TechDocs Markdown extension configuration

Published Oct 7, 2026
·
Updated

Impact

An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources.

Patches

Patched in @backstage/plugin-techdocs-node version 1.15.4.

Adopters must also use pymdown-extensions version 10.21.3 or newer, normally through mkdocs-techdocs-core version 1.7.0 or newer. @backstage/plugin-techdocs-node does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized.

Workarounds

- Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. - Use isolated build environments with restricted filesystem access and network egress. - Prefer externally generated TechDocs with appropriately sandboxed CI.

Other sources

Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.

— MITRE

Affected Software

2 affected componentsFixes available
npm/@backstage/plugin-techdocs-node<1.14.6, >=1.15.0<1.15.4
npm/@backstage/plugin-techdocs-node<1.15.4
1.15.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-techdocs-node to a version that resolves this vulnerability.

    Fixed in 1.15.4
  2. Upgrade

    Upgrade @backstage/plugin-techdocs-node to a version that resolves this vulnerability.

    Fixed in 1.15.4
  3. Upgrade

    Upgrade pymdown-extensions to a version that resolves this vulnerability.

    Fixed in 10.21.3
  4. Upgrade

    Upgrade mkdocs-techdocs-core to a version that resolves this vulnerability.

    Fixed in 1.7.0
  5. Compensating control

    Generate TechDocs only from trusted repositories with reviewed MkDocs configuration.

  6. Compensating control

    Prefer externally generated TechDocs using appropriately sandboxed CI.

  7. Compensating control

    Use isolated build environments with restricted filesystem access and network egress.

Event History

Oct 7, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·04:22 PM
Data Sourced
via GitHub·04:22 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue in practice?

An authenticated user must be able to register or modify documentation sources. Deployments that allow untrusted users or repositories to control MkDocs or TechDocs configuration are exposed to the greatest risk.

2

What can a successful exploit access?

A crafted TechDocs build can access resources outside the intended documentation boundary. Depending on the deployment, this can expose sensitive data on the backend host or reach internal network resources.

3

Is upgrading only @backstage/plugin-techdocs-node sufficient?

No. In addition to upgrading @backstage/plugin-techdocs-node to 1.15.4, the generator must use pymdown-extensions 10.21.3 or newer, normally via mkdocs-techdocs-core 1.7.0 or newer; older PyMdown versions may still permit file inclusion through snippets.

4

What mitigations are available before patching?

Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. Isolate build environments, restrict their filesystem access and network egress, or use externally generated TechDocs built in appropriately sandboxed CI.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203