PT-2026-107532 · Backstage · Backstage

CVE-2026-106556

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Backstage versions prior to 1.14.6
Description The @backstage/plugin-techdocs-node package contains a configuration bypass during the sanitization of mkdocs.yml. Insufficient validation of the MkDocs configuration during TechDocs generation allows an authenticated user with permissions to register or modify documentation sources to execute arbitrary commands within the build environment. The impact is restricted to resources accessible by the TechDocs backend or the build container.
Recommendations Update to version 1.14.6 or 1.15.4.

Exploit

Fix

Incomplete List of Disallowed Inputs

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106556
GHSA-G2HJ-V2J6-VFVG

Affected Products

Backstage