PT-2026-107310 · Npm+2 · @Backstage/Plugin-Techdocs-Node+2

CVE-2026-106509

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L

Impact

When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process.

Patches

Patched in @backstage/plugin-techdocs-node version 1.15.4

Workarounds

  • Configure TechDocs with techdocs.generator.runIn: 'docker' instead of 'local' to provide container isolation, though this does not fully mitigate the risk.
  • Restrict write access to repositories registered in the Backstage catalog to trusted users.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106509
GHSA-8W7Q-29MW-GF5C

Affected Products

@Backstage/Plugin-Techdocs-Node
Backstage
Plugin-Techdocs-Node