OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-106509: Backstage: Improper validation of MkDocs theme configuration in TechDocs

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

### Impact When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in `mkdocs.yml` that cause arbitrary code execution during the documentation build process. ### Patches Patched in `@backstage/plugin-techdocs-node` version `1.15.4` ### Workarounds - Configure TechDocs with `techdocs.generator.runIn: 'docker'` instead of `'local'` to provide container isolation, though this does not fully mitigate the risk. - Restrict write access to repositories registered in the Backstage catalog to trusted users.

Upgrade affected packages to a patched version: @backstage/plugin-techdocs-node 1.15.4.

Vendor
Not specified
Product
@backstage/plugin-techdocs-node
Exploitation
none known
Evidence
official
CVSS
7.7

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source