OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-106557: Backstage has improper input validation in TechDocs Markdown extension configuration

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

### Impact An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources. ### Patches Patched in `@backstage/plugin-techdocs-node` version `1.15.4`. Adopters must also use `pymdown-extensions` version `10.21.3` or newer, normally through `mkdocs-techdocs-core` version `1.7.0` or newer. `@backstage/plugin-techdocs-node` does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized. ### Workarounds - Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. - Use isolated build environments with restricted filesystem access and network egress. - Prefer externally generated TechDocs with appropriately sandboxed CI.

Upgrade affected packages to a patched version: @backstage/plugin-techdocs-node 1.15.4.

Vendor
Not specified
Product
@backstage/plugin-techdocs-node
Exploitation
none known
Evidence
official
CVSS
7.7

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source