CVE-2026-106507
Received Received - Intake

TechDocs Arbitrary File Read in Backstage

Vulnerability report for CVE-2026-106507, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
backstage backstage < 1.54.6
@backstage/plugin-techdocs-node plugin-techdocs-node < 1.15.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the @backstage/plugin-techdocs-node package in Backstage versions before 1.15.4. It allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary through unsafe path resolution in TechDocs source tree handling. This may expose files readable by the build process.

Impact Analysis

An attacker with access to register documentation sources could read sensitive files on the system that are accessible by the build process. This could lead to unauthorized access to confidential or proprietary information depending on deployment configuration.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, potentially violating GDPR or HIPAA compliance if such data is exposed. Organizations must ensure proper access controls and apply the patch to maintain compliance.

Mitigation Strategies

Upgrade the @backstage/plugin-techdocs-node package to version 1.15.4 or later to address the arbitrary file read vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106507. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart