CVE-2026-106558: Backstage: Improper validation of TechDocs MkDocs configuration
### Impact An attacker who can provide configuration to a TechDocs build may execute code in the generator runtime. Impact is greatest when documentation generation runs with backend credentials or host access. ### Patches Patched in `@backstage/plugin-techdocs-node` version `1.15.4`. ### Workarounds Use external TechDocs generation in an isolated environment without sensitive credentials or host access. Restrict and review changes to documentation configuration before generation.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/plugin-techdocs-node 1.15.4.
Technical details
- Vendor
- Not specified
- Product
- @backstage/plugin-techdocs-node
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source