Insufficient Input Validation in Backstage Plugin Affecting Documentation Generation
CVE-2026-88064

8.8HIGH

Key Information:

Vendor

Backstage

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-88064?

The @backstage/plugin-techdocs-node package within the Backstage framework has a vulnerability that stems from inadequate validation of mkdocs.yml files uploaded by authenticated users. This flaw enables the injection of unsafe Python YAML tags and configurations, which can lead to unintended code execution in the documentation generator. The impact is mitigated by the user's available resources, including files, credentials, and network access, subjected to the TechDocs backend or build container. The issue has been addressed in versions 1.14.6 and 1.15.4, ensuring enhanced security for documentation-related operations.

Affected Version(s)

backstage < 1.14.6 < 1.14.6

backstage >= 1.15.0, < 1.15.4 < 1.15.0, 1.15.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.