CVE-2026-106557: Backstage has improper input validation in TechDocs Markdown extension configuration
### Impact An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources. ### Patches Patched in `@backstage/plugin-techdocs-node` version `1.15.4`. Adopters must also use `pymdown-extensions` version `10.21.3` or newer, normally through `mkdocs-techdocs-core` version `1.7.0` or newer. `@backstage/plugin-techdocs-node` does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized. ### Workarounds - Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. - Use isolated build environments with restricted filesystem access and network egress. - Prefer externally generated TechDocs with appropriately sandboxed CI.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/plugin-techdocs-node 1.15.4.
Technical details
- Vendor
- Not specified
- Product
- @backstage/plugin-techdocs-node
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source