Path Traversal Vulnerability in Backstage Developer Portal Plugin
CVE-2026-25152
What is CVE-2026-25152?
The @backstage/plugin-techdocs-node plugin for Backstage is susceptible to a path traversal vulnerability that allows attackers to access arbitrary files within the host filesystem. This occurs when the TechDocs local generator is employed with the configuration setting techdocs.generator.runIn: local. When documentation containing symlinks is processed from untrusted sources, MkDocs follows these symlinks during its build process, potentially exposing sensitive file contents in generated HTML. To mitigate risks, users should upgrade to versions 1.13.11 or 1.14.1 or configure their setup to use runIn: docker in app-config.yaml, alongside restricting write access to trusted contributors only.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
backstage < 1.13.11 < 1.13.11
backstage = 1.14.0 = 1.14.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
