PT-2026-107582 · Backstage+2 · Backstage+3

CVE-2026-106557

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Backstage versions prior to 1.14.6 Backstage versions prior to 1.15.4
Description The @backstage/plugin-techdocs-node package fails to sufficiently validate TechDocs Markdown extension configuration. An authenticated user with permissions to register or modify documentation sources can trigger a TechDocs build to access resources outside the intended documentation boundary. This may lead to the exposure of sensitive backend-host data or internal network resources.
Recommendations Update to version 1.14.6 and ensure pymdown-extensions version 10.21.3 or later is used, typically via mkdocs-techdocs-core version 1.7.0 or later. Update to version 1.15.4 and ensure pymdown-extensions version 10.21.3 or later is used, typically via mkdocs-techdocs-core version 1.7.0 or later. Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. Use isolated build environments with restricted filesystem access and network egress. Prefer externally generated TechDocs with appropriately sandboxed CI.

Exploit

Fix

SSRF

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106557
GHSA-F7V3-XHM6-W245

Affected Products

@Backstage/Plugin-Techdocs-Node
Backstage
Mkdocs-Techdocs-Core
Pymdown Extensions