GHSA-4488-j8vj-vqqv: High severity npm/@backstage/plugin-techdocs-node vulnerability

Published Oct 7, 2026
·
Updated

Impact

An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built.

Patches

Patched in @backstage/plugin-techdocs-node, version 1.15.4.

Workarounds

If you cannot upgrade immediately:

- Switch to techdocs.builder: external to isolate TechDocs builds in a container. - Restrict who can register catalog entities with TechDocs annotations. - Audit existing catalog entities for suspicious markdownextensions values in their mkdocs.yml files.

Affected Software

1 affected componentFixes available
npm/@backstage/plugin-techdocs-node<1.15.4
1.15.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-techdocs-node to a version that resolves this vulnerability.

    Fixed in 1.15.4
  2. Upgrade

    Upgrade @backstage/plugin-techdocs-node to a version that resolves this vulnerability.

    Fixed in 1.15.4
  3. Configuration

    Set `techdocs.builder: external` to isolate TechDocs builds in a container.

    TechDocs techdocs.builder = external
  4. Compensating control

    Audit existing catalog entities for suspicious `markdown_extensions` values in their `mkdocs.yml` files.

  5. Compensating control

    Restrict who can register catalog entities with TechDocs annotations.

Event History

Oct 7, 2026
Advisory Published
via GitHub·06:03 PM
Data Sourced
via GitHub·06:03 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this vulnerability?

An authenticated user who is permitted to register catalog entities and can supply a crafted mkdocs.yml for TechDocs can trigger command execution when the documentation is built.

2

Are deployments using the external TechDocs builder affected in the same way?

Using techdocs.builder: external is listed as a workaround because it isolates TechDocs builds in a container. The described command execution occurs on the TechDocs build host.

3

What should teams do if they cannot upgrade immediately?

Switch to techdocs.builder: external, restrict who can register catalog entities with TechDocs annotations, and audit existing catalog entities for suspicious markdown_extensions values in mkdocs.yml files.

4

How can I identify potentially malicious existing content?

Audit catalog entities that use TechDocs and inspect their mkdocs.yml files for suspicious markdown_extensions values.

5

What version contains the fix?

The issue is patched in @backstage/plugin-techdocs-node version 1.15.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203