Disclosure summary
### Impact Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. ### Patches Patched in`@backstage/plugin-techdocs-node` version `1.15.4` ### Workarounds If you cannot upgrade immediately: - Use Docker mode with restricted access: Configure TechDocs with `runIn: docker` instead of `runIn: local`. This provides container isolation, though it does not fully mitigate the risk. - Limit repository write access to trusted parties, since exploitation requires the ability to commit files to a repository with TechDocs enabled. - Review incoming changes to MkDocs configuration files as part of your code review process.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-p75x-jh7p-ppcx
Open original source · Updated Oct 07, 2026
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @backstage/plugin-techdocs-node | < 1.15.4 | 1.15.4 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:23:52-04:00
MODIFIED 2026-10-07T12:23:54-04:00
INGESTED 2026-10-08T12:05:11-04:00