GHSA-8w7q-29mw-gf5c: Code Injection
Impact
When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4
Workarounds
- Configure TechDocs with techdocs.generator.runIn: 'docker' instead of 'local' to provide container isolation, though this does not fully mitigate the risk. - Restrict write access to repositories registered in the Backstage catalog to trusted users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Configuration
Configure TechDocs to use techdocs.generator.runIn: 'docker' instead of 'local' to provide container isolation.
TechDocs techdocs.generator.runIn = docker - Compensating control
Restrict write access to repositories registered in the Backstage catalog to trusted users.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs write access to a repository registered in the Backstage catalog. They can place malicious configuration values in that repository's mkdocs.yml file.
Which TechDocs configurations are exposed?
TechDocs configurations that build documentation locally or in a container are affected. Container execution provides isolation but does not fully mitigate the risk.
What can be done before updating?
Set techdocs.generator.runIn to 'docker' rather than 'local' and restrict write access to registered catalog repositories to trusted users. This is only a partial mitigation; updating remains necessary.
What version contains the patch?
The issue is patched in @backstage/plugin-techdocs-node version 1.15.4.