PT-2026-107533 · Npm · @Backstage/Plugin-Techdocs-Node

CVE-2026-106558

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @backstage/plugin-techdocs-node versions prior to 1.14.8 @backstage/plugin-techdocs-node versions prior to 1.15.6 @backstage/plugin-techdocs-node versions prior to 2.0.1
Description The @backstage/plugin-techdocs-node package improperly validates the mapping-style markdown extensions configuration. An authenticated attacker capable of registering or influencing an SCM-backed documentation source can bypass sanitization to import and instantiate Python objects within the generator runtime, resulting in arbitrary code execution. The risk is higher if documentation generation occurs with backend credentials, filesystem access, or internal network access.
Recommendations Update @backstage/plugin-techdocs-node to version 1.14.8. Update @backstage/plugin-techdocs-node to version 1.15.6. Update @backstage/plugin-techdocs-node to version 2.0.1. Use external TechDocs generation in an isolated environment without sensitive credentials or host access. Restrict and review changes to documentation configuration before generation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106558
GHSA-QMW3-745M-W99G

Affected Products

@Backstage/Plugin-Techdocs-Node