CVE-2026-106505: Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
### Impact Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. ### Patches Patched in`@backstage/plugin-techdocs-node` version `1.15.4` ### Workarounds If you cannot upgrade immediately: - Use Docker mode with restricted access: Configure TechDocs with `runIn: docker` instead of `runIn: local`. This provides container isolation, though it does not fully mitigate the risk. - Limit repository write access to trusted parties, since exploitation requires the ability to commit files to a repository with TechDocs enabled. - Review incoming changes to MkDocs configuration files as part of your code review process.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/plugin-techdocs-node 1.15.4.
Technical details
- Vendor
- Not specified
- Product
- @backstage/plugin-techdocs-node
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source