CVE-2026-106557: Backstage: Improper input validation in TechDocs Markdown extension configuration
Impact
An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4.
Adopters must also use pymdown-extensions version 10.21.3 or newer, normally through mkdocs-techdocs-core version 1.7.0 or newer. @backstage/plugin-techdocs-node does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized.
Workarounds
- Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. - Use isolated build environments with restricted filesystem access and network egress. - Prefer externally generated TechDocs with appropriately sandboxed CI.
Other sources
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Upgrade
Upgrade
pymdown-extensionsto a version that resolves this vulnerability.Fixed in 10.21.3 - Upgrade
Upgrade
mkdocs-techdocs-coreto a version that resolves this vulnerability.Fixed in 1.7.0 - Compensating control
Generate TechDocs only from trusted repositories with reviewed MkDocs configuration.
- Compensating control
Prefer externally generated TechDocs using appropriately sandboxed CI.
- Compensating control
Use isolated build environments with restricted filesystem access and network egress.
Event History
Frequently Asked Questions
Who can exploit this issue in practice?
An authenticated user must be able to register or modify documentation sources. Deployments that allow untrusted users or repositories to control MkDocs or TechDocs configuration are exposed to the greatest risk.
What can a successful exploit access?
A crafted TechDocs build can access resources outside the intended documentation boundary. Depending on the deployment, this can expose sensitive data on the backend host or reach internal network resources.
Is upgrading only @backstage/plugin-techdocs-node sufficient?
No. In addition to upgrading @backstage/plugin-techdocs-node to 1.15.4, the generator must use pymdown-extensions 10.21.3 or newer, normally via mkdocs-techdocs-core 1.7.0 or newer; older PyMdown versions may still permit file inclusion through snippets.
What mitigations are available before patching?
Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. Isolate build environments, restrict their filesystem access and network egress, or use externally generated TechDocs built in appropriately sandboxed CI.