CVE-2026-106510: Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml
### Impact An authenticated user who can register catalog entities can provide a crafted `mkdocs.yml` causing arbitrary OS command execution on the TechDocs build host when the docs are built. ### Patches Patched in `@backstage/plugin-techdocs-node`, version `1.15.4`. ### Workarounds If you cannot upgrade immediately: - Switch to `techdocs.builder: external` to isolate TechDocs builds in a container. - Restrict who can register catalog entities with TechDocs annotations. - Audit existing catalog entities for suspicious `markdown_extensions` values in their `mkdocs.yml` files.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/plugin-techdocs-node 1.15.4.
Technical details
- Vendor
- Not specified
- Product
- @backstage/plugin-techdocs-node
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source