CVE-2026-106508
Received Received - Intake

File Exposure in Backstage TechDocs Local Publisher

Vulnerability report for CVE-2026-106508, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
backstage backstage < 1.54.6
@backstage plugin-techdocs-node < 1.15.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Backstage is an open framework for building developer portals. The @backstage/plugin-techdocs-node package before version 1.15.4 has a vulnerability where the local TechDocs publisher could expose host files outside the intended documentation directory. This happens when the documentation serving endpoint follows filesystem references beyond the documentation tree, potentially allowing authenticated users to access sensitive host files. Cloud-based publishers like S3, GCS, or Azure Blob Storage are not affected.

Detection Guidance

To detect this vulnerability, check if your Backstage instance uses the local TechDocs publisher (techdocs.publisher.type: 'local'). Verify the version of @backstage/plugin-techdocs-node is below 1.15.4. Inspect server logs for unauthorized file access attempts or unusual filesystem traversal patterns.

Impact Analysis

If you use the local TechDocs publisher in Backstage versions before 1.15.4, an authenticated attacker could access files outside the intended documentation directory on your host system. This may lead to unauthorized access to sensitive files, depending on the host's file permissions and configuration.

Compliance Impact

This vulnerability could potentially expose sensitive data, which may violate compliance requirements under GDPR or HIPAA if unauthorized access occurs. Organizations using affected versions should update to version 1.15.4 or later to mitigate risks.

Mitigation Strategies

Upgrade @backstage/plugin-techdocs-node to version 1.15.4 or later. If using the local publisher, consider switching to a cloud-based publisher (S3, GCS, Azure Blob Storage) to avoid exposure. Review and restrict filesystem permissions for the TechDocs directory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106508. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart