Plugin techdocs node: Backstage: Improper validation of MkDocs plugin configuration in TechDocs (CVE-2026-106455)
Description
An authenticated attacker with control over a TechDocs source repository in the Backstage plugin techdocs node can cause a documentation build to retrieve and publish data from network locations accessible by the build environment. The exposure depends on deployment topology, build mode, and endpoint protections. The vulnerability is addressed by upgrading to patched versions that remove MkDocs plugins outside a built-in allowlist. Additional mitigations include restricting repository control and limiting network access during builds.
CVSS v3.1
Score 7.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-106455 is a vulnerability in the Backstage @backstage/plugin-techdocs-node component where improper validation of MkDocs plugin configuration allows an authenticated attacker controlling a TechDocs source repository to cause documentation builds to fetch and publish data from network locations reachable by the build environment. The vulnerability's impact varies based on deployment and network protections. The fix involves upgrading to patched versions (1.14.7+, 1.15.5+, or 2.0.0+) which enforce a built-in allowlist of MkDocs plugins, removing unauthorized plugins. Configuration options exist to allow additional plugins after review.
Potential Impact
An attacker with authenticated access to a TechDocs source repository can manipulate documentation builds to access and publish data from internal or network locations accessible to the build environment. This could lead to unauthorized data exposure. The vulnerability does not directly expose modern cloud metadata services that require tokens or special headers. The severity is high with a CVSS score of 7.7, indicating significant confidentiality impact but no integrity or availability impact.
Mitigation Recommendations
Upgrade @backstage/plugin-techdocs-node to 1.14.7 or later for the 1.14.x line, 1.15.5 or later for the 1.15.x line, or 2.0.0 or later for the mainline. These updates remove MkDocs plugins outside the built-in allowlist. To retain additional plugins, review and explicitly configure them using 'techdocs.generator.mkdocs.dangerouslyAllowAdditionalPlugins'. Additionally, restrict control of TechDocs source repositories to trusted maintainers, run documentation builders with outbound access to private and link-local networks denied, and require token- or header-protected cloud instance metadata services to prevent unauthorized access.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-q38j-6vcm-2f5m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-106455"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ac6bfb72cdf04f656828ca0
Added to database: 10/07/2026, 21:55:03 UTC
Last enriched: 10/07/2026, 21:58:03 UTC
Last updated: 10/07/2026, 21:58:03 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.