File Exposure Vulnerability in Backstage Plugin by Backstage
CVE-2026-106508
What is CVE-2026-106508?
The @backstage/plugin-techdocs-node package prior to version 1.15.4 has a vulnerability that may allow authenticated users to access unintended files through the local TechDocs publisher. Specifically, when utilizing the local publisher (techdocs.publisher.type: 'local'), the documentation serving endpoint can mistakenly follow filesystem references beyond the specific documentation directory, leading to potential exposure of sensitive host files. Although this situation necessitates unusual preconditions that typically do not occur in standard MkDocs operations, it remains a significant concern for users of the affected version. It's important to note that cloud-based publishers such as S3, GCS, and Azure Blob Storage are unaffected. This issue has been resolved in version 1.15.4.
Affected Version(s)
backstage < 1.54.6
plugin-techdocs-node < 1.15.4
