Improper Validation in Backstage’s TechDocs Plugin Affects Documentation Builds
CVE-2026-106509
7.7HIGH
What is CVE-2026-106509?
The @backstage/plugin-techdocs-node package in Backstage prior to version 1.14.6 is susceptible to a serious flaw where improper validation of mkdocs theme configurations permits a user with write access to introduce malicious code execution during the documentation building process. This risk arises when TechDocs is set up to build documentation either locally or within a container, thus allowing potentially dangerous configurations to be included in mkdocs.yml. The issue was remediated in versions 1.14.6 and 1.15.4, emphasizing the necessity for users to upgrade to secure their documentation processes.
Affected Version(s)
backstage < 1.50.5 < 1.50.5
backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6
plugin-techdocs-node < 1.14.6 < 1.14.6
