GHSA-f7v3-xhm6-w245: Path Traversal

Published Oct 7, 2026
·
Updated

Impact

An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources.

Patches

Patched in @backstage/plugin-techdocs-node version 1.15.4.

Adopters must also use pymdown-extensions version 10.21.3 or newer, normally through mkdocs-techdocs-core version 1.7.0 or newer. @backstage/plugin-techdocs-node does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized.

Workarounds

- Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. - Use isolated build environments with restricted filesystem access and network egress. - Prefer externally generated TechDocs with appropriately sandboxed CI.

Affected Software

1 affected componentFixes available
npm/@backstage/plugin-techdocs-node<1.15.4
1.15.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-techdocs-node to a version that resolves this vulnerability.

    Fixed in 1.15.4
  2. Upgrade

    Upgrade @backstage/plugin-techdocs-node to a version that resolves this vulnerability.

    Fixed in 1.15.4
  3. Upgrade

    Upgrade pymdown-extensions to a version that resolves this vulnerability.

    Fixed in 10.21.3
  4. Upgrade

    Upgrade mkdocs-techdocs-core to a version that resolves this vulnerability.

    Fixed in 1.7.0
  5. Compensating control

    Generate TechDocs only from trusted repositories with reviewed MkDocs configuration.

  6. Compensating control

    Prefer externally generated TechDocs with appropriately sandboxed CI.

  7. Compensating control

    Use isolated build environments with restricted filesystem access and network egress.

Event History

Oct 7, 2026
Advisory Published
via GitHub·04:22 PM
Data Sourced
via GitHub·04:22 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue in practice?

An authenticated user who is permitted to register or modify documentation sources can exploit it. Deployments that allow untrusted repositories or unreviewed MkDocs configuration to supply TechDocs content are the primary exposure.

2

What could a successful exploit reach?

A TechDocs build may access files or resources outside the intended documentation boundary. Depending on the deployment configuration, this can expose sensitive data available to the build backend or resources on internal networks.

3

What needs to be updated to fully remediate the issue?

Update @backstage/plugin-techdocs-node to version 1.15.4 and ensure pymdown-extensions is version 10.21.3 or later, normally by using mkdocs-techdocs-core 1.7.0 or later. Updating only the Node package is insufficient when the generator still uses an older PyMdown release.

4

What can be done if updates cannot be applied immediately?

Build TechDocs only from trusted repositories with reviewed MkDocs configuration. Run builds in isolated environments with restricted filesystem access and network egress, or use externally generated TechDocs from appropriately sandboxed CI.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203