CVE-2026-106509: Backstage: Improper validation of MkDocs theme configuration in TechDocs
### Impact When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in `mkdocs.yml` that cause arbitrary code execution during the documentation build process. ### Patches Patched in `@backstage/plugin-techdocs-node` version `1.15.4` ### Workarounds - Configure TechDocs with `techdocs.generator.runIn: 'docker'` instead of `'local'` to provide container isolation, though this does not fully mitigate the risk. - Restrict write access to repositories registered in the Backstage catalog to trusted users.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/plugin-techdocs-node 1.15.4.
Technical details
- Vendor
- Not specified
- Product
- @backstage/plugin-techdocs-node
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source