CVE-2026-106556
Awaiting Analysis Awaiting Analysis - Queue

Configuration Bypass in Backstage TechDocs Node Plugin

Vulnerability report for CVE-2026-106556, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configuration bypass in techdocs mkdocs.yml sanitization. Insufficient validation of MkDocs configuration during TechDocs generation could allow an authenticated user who can register or modify documentation sources to execute arbitrary commands in the build environment. Impact is limited to resources accessible to the TechDocs backend or build container. This issue is fixed in versions 1.14.6 and 1.15.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
backstage backstage < 1.50.5
backstage backstage >= 1.51.0-next.0, < 1.54.6
@backstage plugin-techdocs-node < 1.14.6
@backstage plugin-techdocs-node >= 1.15.0, < 1.15.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a configuration bypass in the TechDocs plugin for Backstage. It affects the mkdocs.yml sanitization process during documentation generation in versions prior to 1.14.6 and between 1.15.0 and 1.15.3. Insufficient validation allows authenticated users who can modify documentation sources to execute arbitrary commands in the build environment.

Detection Guidance

Check Backstage and TechDocs plugin versions. Run: npm list @backstage/plugin-techdocs-node. If version is below 1.14.6 or between 1.15.0-1.15.3, the system is vulnerable. Inspect mkdocs.yml files for unsafe Python YAML tags like !!python/name:builtins.str or !!python/object/apply:builtins.str.

Impact Analysis

An attacker with access to modify documentation sources could execute arbitrary commands within the TechDocs build environment. This could lead to unauthorized code execution, data exfiltration, or disruption of services limited to the TechDocs backend or build container.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized command execution in the build environment. If exploited, it may lead to unauthorized access to sensitive data processed or stored within the TechDocs backend or build container, violating data protection requirements under these regulations.

Mitigation Strategies

Upgrade @backstage/plugin-techdocs-node to version 1.14.6 or 1.15.4 or later. If immediate upgrade is not possible, enable Docker mode with restricted access, restrict repository access to trusted contributors, or implement manual review for mkdocs.yml changes. Disable unsafe Python YAML tags in MkDocs configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106556. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart