Path Traversal Vulnerability in Backstage Developer Portal Plugin
CVE-2026-25152

5.3MEDIUM

Key Information:

Vendor

Backstage

Status
Vendor
CVE Published:
30 January 2026

What is CVE-2026-25152?

The @backstage/plugin-techdocs-node plugin for Backstage is susceptible to a path traversal vulnerability that allows attackers to access arbitrary files within the host filesystem. This occurs when the TechDocs local generator is employed with the configuration setting techdocs.generator.runIn: local. When documentation containing symlinks is processed from untrusted sources, MkDocs follows these symlinks during its build process, potentially exposing sensitive file contents in generated HTML. To mitigate risks, users should upgrade to versions 1.13.11 or 1.14.1 or configure their setup to use runIn: docker in app-config.yaml, alongside restricting write access to trusted contributors only.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

backstage < 1.13.11 < 1.13.11

backstage = 1.14.0 = 1.14.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.