CVE-2026-106557: @backstage Plugin-Techdocs-Node
High severity, CVSS 7.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.
Affected products
- @backstage Plugin-Techdocs-Node: before 1.14.6 (fixed in 1.14.6); from 1.15.0, before 1.15.4 (fixed in 1.15.4)
- Backstage Backstage: before 1.50.5 (fixed in 1.50.5); from 1.51.0-next.0, before 1.54.6 (fixed in 1.54.6)
Published 2026-10-07. Last modified 2026-10-08.