CVE-2026-106557
Received Received - Intake

TechDocs Markdown Extension Misconfiguration in Backstage

Vulnerability report for CVE-2026-106557, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
backstage backstage < 1.50.5
backstage backstage >= 1.51.0-next.0, < 1.54.6
@backstage plugin-techdocs-node < 1.14.6
@backstage plugin-techdocs-node >= 1.15.0, < 1.15.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-106557 is a vulnerability in the @backstage/plugin-techdocs-node package where insufficient validation of TechDocs Markdown extension configuration allows path traversal and SSRF attacks. An authenticated user with documentation source modification rights can access backend data or internal network resources outside intended boundaries.

Detection Guidance

To detect this vulnerability, check the version of @backstage/plugin-techdocs-node in your Backstage installation. Run: npm list @backstage/plugin-techdocs-node. If the version is below 1.14.6 or between 1.15.0 and 1.15.3, the system is vulnerable.

Impact Analysis

This vulnerability may allow unauthorized access to sensitive backend-hosted data or internal network resources. Attackers could exploit it to read restricted files or trigger unintended external requests, potentially leading to data breaches or further network compromise.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations may face compliance violations, legal penalties, or reputational damage if sensitive data is accessed through this flaw.

Mitigation Strategies

Update @backstage/plugin-techdocs-node to version 1.15.4 or later. Ensure pymdown-extensions is at least version 10.21.3, typically via mkdocs-techdocs-core 1.7.0 or newer. Review and restrict TechDocs build environments to trusted repositories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106557. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart