CVE-2026-106558
Awaiting Analysis Awaiting Analysis - Queue

Code Execution in Backstage TechDocs Node Plugin

Vulnerability report for CVE-2026-106558, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can register or influence an SCM-backed documentation source may bypass TechDocs sanitization and cause Python objects to be imported and instantiated in the generator runtime, leading to arbitrary code execution. Earlier fixes in versions 1.14.6 and 1.15.4 did not fully address the supported mapping representation of markdown_extensions. Impact is greatest when documentation generation runs with backend credentials, filesystem access, or internal network access. This issue is fixed in versions 1.14.8, 1.15.6, and 2.0.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
backstage backstage < 1.50.7
backstage backstage >= 1.51.0-next.0, < 1.54.9
backstage backstage >= 1.55.0-next.0, < 1.55.2
@backstage plugin-techdocs-node < 1.14.8
@backstage plugin-techdocs-node >= 1.15.0, < 1.15.6
@backstage plugin-techdocs-node >= 2.0.0, < 2.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the @backstage/plugin-techdocs-node package in Backstage versions before 1.14.8, 1.15.6, and 2.0.1. It involves improper validation of the markdown_extensions configuration in TechDocs, allowing an authenticated attacker with SCM-backed documentation source access to bypass sanitization and cause Python objects to be imported during documentation generation. This leads to arbitrary code execution, especially when generation runs with backend credentials or filesystem access.

Detection Guidance

Check if your Backstage instance uses affected versions of @backstage/plugin-techdocs-node (<1.14.8, >=1.15.0 <1.15.6, >=2.0.0 <2.0.1). Inspect mkdocs.yml files for unsafe markdown_extensions configurations like subprocess:Popen, os:system, or !ENV tags. Review TechDocs generation logs for Python object instantiation errors or unexpected commands.

Impact Analysis
  • Unauthorized code execution on systems running vulnerable Backstage versions, potentially leading to data breaches or system compromise.
  • Loss of confidentiality, integrity, and availability of backend systems if documentation generation runs with elevated privileges.
  • Compromise of internal networks or filesystems if the attacker exploits the vulnerability to gain access to sensitive resources.
Compliance Impact

This vulnerability could lead to unauthorized access or data exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using vulnerable versions may face compliance violations, legal penalties, and reputational damage due to potential breaches of confidentiality and integrity.

Mitigation Strategies

Upgrade to patched versions (1.14.8, 1.15.6, or 2.0.1). Disable TechDocs generation with sensitive credentials or isolate generation in a restricted environment. Review and sanitize all mkdocs.yml files to remove dangerous markdown_extensions configurations. Monitor for unauthorized Python object instantiation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106558. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart