OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-106510: Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

### Impact An authenticated user who can register catalog entities can provide a crafted `mkdocs.yml` causing arbitrary OS command execution on the TechDocs build host when the docs are built. ### Patches Patched in `@backstage/plugin-techdocs-node`, version `1.15.4`. ### Workarounds If you cannot upgrade immediately: - Switch to `techdocs.builder: external` to isolate TechDocs builds in a container. - Restrict who can register catalog entities with TechDocs annotations. - Audit existing catalog entities for suspicious `markdown_extensions` values in their `mkdocs.yml` files.

Upgrade affected packages to a patched version: @backstage/plugin-techdocs-node 1.15.4.

Vendor
Not specified
Product
@backstage/plugin-techdocs-node
Exploitation
none known
Evidence
official
CVSS
7.7

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source