File Exposure Vulnerability in Backstage Plugin by Backstage
CVE-2026-106508

5.3MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106508?

The @backstage/plugin-techdocs-node package prior to version 1.15.4 has a vulnerability that may allow authenticated users to access unintended files through the local TechDocs publisher. Specifically, when utilizing the local publisher (techdocs.publisher.type: 'local'), the documentation serving endpoint can mistakenly follow filesystem references beyond the specific documentation directory, leading to potential exposure of sensitive host files. Although this situation necessitates unusual preconditions that typically do not occur in standard MkDocs operations, it remains a significant concern for users of the affected version. It's important to note that cloud-based publishers such as S3, GCS, and Azure Blob Storage are unaffected. This issue has been resolved in version 1.15.4.

Affected Version(s)

backstage < 1.54.6

plugin-techdocs-node < 1.15.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.