Improper Validation in Backstage’s TechDocs Plugin Affects Documentation Builds
CVE-2026-106509

7.7HIGH

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106509?

The @backstage/plugin-techdocs-node package in Backstage prior to version 1.14.6 is susceptible to a serious flaw where improper validation of mkdocs theme configurations permits a user with write access to introduce malicious code execution during the documentation building process. This risk arises when TechDocs is set up to build documentation either locally or within a container, thus allowing potentially dangerous configurations to be included in mkdocs.yml. The issue was remediated in versions 1.14.6 and 1.15.4, emphasizing the necessity for users to upgrade to secure their documentation processes.

Affected Version(s)

backstage < 1.50.5 < 1.50.5

backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6

plugin-techdocs-node < 1.14.6 < 1.14.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.