GHSA-4488-j8vj-vqqv: High severity npm/@backstage/plugin-techdocs-node vulnerability
Impact
An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built.
Patches
Patched in @backstage/plugin-techdocs-node, version 1.15.4.
Workarounds
If you cannot upgrade immediately:
- Switch to techdocs.builder: external to isolate TechDocs builds in a container. - Restrict who can register catalog entities with TechDocs annotations. - Audit existing catalog entities for suspicious markdownextensions values in their mkdocs.yml files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Configuration
Set `techdocs.builder: external` to isolate TechDocs builds in a container.
TechDocs techdocs.builder = external - Compensating control
Audit existing catalog entities for suspicious `markdown_extensions` values in their `mkdocs.yml` files.
- Compensating control
Restrict who can register catalog entities with TechDocs annotations.
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An authenticated user who is permitted to register catalog entities and can supply a crafted mkdocs.yml for TechDocs can trigger command execution when the documentation is built.
Are deployments using the external TechDocs builder affected in the same way?
Using techdocs.builder: external is listed as a workaround because it isolates TechDocs builds in a container. The described command execution occurs on the TechDocs build host.
What should teams do if they cannot upgrade immediately?
Switch to techdocs.builder: external, restrict who can register catalog entities with TechDocs annotations, and audit existing catalog entities for suspicious markdown_extensions values in mkdocs.yml files.
How can I identify potentially malicious existing content?
Audit catalog entities that use TechDocs and inspect their mkdocs.yml files for suspicious markdown_extensions values.
What version contains the fix?
The issue is patched in @backstage/plugin-techdocs-node version 1.15.4.