GHSA-f7v3-xhm6-w245: Path Traversal
Impact
An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4.
Adopters must also use pymdown-extensions version 10.21.3 or newer, normally through mkdocs-techdocs-core version 1.7.0 or newer. @backstage/plugin-techdocs-node does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized.
Workarounds
- Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. - Use isolated build environments with restricted filesystem access and network egress. - Prefer externally generated TechDocs with appropriately sandboxed CI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Upgrade
Upgrade
@backstage/plugin-techdocs-nodeto a version that resolves this vulnerability.Fixed in 1.15.4 - Upgrade
Upgrade
pymdown-extensionsto a version that resolves this vulnerability.Fixed in 10.21.3 - Upgrade
Upgrade
mkdocs-techdocs-coreto a version that resolves this vulnerability.Fixed in 1.7.0 - Compensating control
Generate TechDocs only from trusted repositories with reviewed MkDocs configuration.
- Compensating control
Prefer externally generated TechDocs with appropriately sandboxed CI.
- Compensating control
Use isolated build environments with restricted filesystem access and network egress.
Event History
Frequently Asked Questions
Who can exploit this issue in practice?
An authenticated user who is permitted to register or modify documentation sources can exploit it. Deployments that allow untrusted repositories or unreviewed MkDocs configuration to supply TechDocs content are the primary exposure.
What could a successful exploit reach?
A TechDocs build may access files or resources outside the intended documentation boundary. Depending on the deployment configuration, this can expose sensitive data available to the build backend or resources on internal networks.
What needs to be updated to fully remediate the issue?
Update @backstage/plugin-techdocs-node to version 1.15.4 and ensure pymdown-extensions is version 10.21.3 or later, normally by using mkdocs-techdocs-core 1.7.0 or later. Updating only the Node package is insufficient when the generator still uses an older PyMdown release.
What can be done if updates cannot be applied immediately?
Build TechDocs only from trusted repositories with reviewed MkDocs configuration. Run builds in isolated environments with restricted filesystem access and network egress, or use externally generated TechDocs from appropriately sandboxed CI.