Configuration Bypass in Backstage TechDocs Plugin by Backstage
CVE-2026-106556
7.7HIGH
What is CVE-2026-106556?
The Backstage TechDocs plugin is vulnerable to a configuration bypass issue in the mkdocs.yml sanitization process. This vulnerability allows authenticated users with permissions to register or modify documentation sources to execute arbitrary commands within the TechDocs build environment. The insufficient validation of MkDocs configuration can lead to exploitation, affecting only resources accessible to the TechDocs backend or build container. It is crucial for users to upgrade to versions 1.14.6 or later to mitigate this risk.
Affected Version(s)
backstage < 1.50.5 < 1.50.5
backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6
plugin-techdocs-node < 1.14.6 < 1.14.6
