Bypass of MkDocs Configuration Sanitize in Backstage Plugin TechDocs Node
CVE-2026-106505

7.7HIGH

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106505?

The Backstage TechDocs Node Plugin is susceptible to a vulnerability where users capable of modifying repository content can bypass the MkDocs configuration file sanitizer. This flaw enables the execution of arbitrary code on the TechDocs backend host during the documentation generation process. The problem has been rectified in versions 1.14.6 and 1.15.4, which provide essential updates to enhance security protocols.

Affected Version(s)

backstage < 1.50.5 < 1.50.5

backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6

plugin-techdocs-node < 1.14.6 < 1.14.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.