Disclosure summary
### Impact An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources. ### Patches Patched in `@backstage/plugin-techdocs-node` version `1.15.4`. Adopters must also use `pymdown-extensions` version `10.21.3` or newer, normally through `mkdocs-techdocs-core` version `1.7.0` or newer. `@backstage/plugin-techdocs-node` does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized. ### Workarounds - Generate TechDocs only from trusted repositories with reviewed MkDocs configuration. - Use isolated build environments with restricted filesystem access and network egress. - Prefer externally generated TechDocs with appropriately sandboxed CI.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-f7v3-xhm6-w245
Open original source · Updated Oct 07, 2026
Backstage has improper input validation in TechDocs Markdown extension configuration
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @backstage/plugin-techdocs-node | < 1.15.4 | 1.15.4 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:22:58-04:00
MODIFIED 2026-10-07T12:22:59-04:00
INGESTED 2026-10-08T12:05:11-04:00