Skip to main content

Plugin techdocs node: Backstage: Improper validation of MkDocs plugin configuration in TechDocs (CVE-2026-106455)

0
High
Published: 10/07/2026 (10/07/2026, 20:25:19 UTC)
Source: GCVE Database
Product: @backstage/plugin-techdocs-node

Description

An authenticated attacker with control over a TechDocs source repository in the Backstage plugin techdocs node can cause a documentation build to retrieve and publish data from network locations accessible by the build environment. The exposure depends on deployment topology, build mode, and endpoint protections. The vulnerability is addressed by upgrading to patched versions that remove MkDocs plugins outside a built-in allowlist. Additional mitigations include restricting repository control and limiting network access during builds.

CVSS v3.1

Score 7.7high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected software

npmghsa
@backstage/plugin-techdocs-node
Affected versions
>=0.11.12 <1.14.7
npmghsa
@backstage/plugin-techdocs-node
Affected versions
>=1.15.0 <1.15.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 21:58:03 UTC

Technical Analysis

CVE-2026-106455 is a vulnerability in the Backstage @backstage/plugin-techdocs-node component where improper validation of MkDocs plugin configuration allows an authenticated attacker controlling a TechDocs source repository to cause documentation builds to fetch and publish data from network locations reachable by the build environment. The vulnerability's impact varies based on deployment and network protections. The fix involves upgrading to patched versions (1.14.7+, 1.15.5+, or 2.0.0+) which enforce a built-in allowlist of MkDocs plugins, removing unauthorized plugins. Configuration options exist to allow additional plugins after review.

Potential Impact

An attacker with authenticated access to a TechDocs source repository can manipulate documentation builds to access and publish data from internal or network locations accessible to the build environment. This could lead to unauthorized data exposure. The vulnerability does not directly expose modern cloud metadata services that require tokens or special headers. The severity is high with a CVSS score of 7.7, indicating significant confidentiality impact but no integrity or availability impact.

Mitigation Recommendations

Upgrade @backstage/plugin-techdocs-node to 1.14.7 or later for the 1.14.x line, 1.15.5 or later for the 1.15.x line, or 2.0.0 or later for the mainline. These updates remove MkDocs plugins outside the built-in allowlist. To retain additional plugins, review and explicitly configure them using 'techdocs.generator.mkdocs.dangerouslyAllowAdditionalPlugins'. Additionally, restrict control of TechDocs source repositories to trusted maintainers, run documentation builders with outbound access to private and link-local networks denied, and require token- or header-protected cloud instance metadata services to prevent unauthorized access.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-q38j-6vcm-2f5m
Osv Schema Version
1.4.0
Aliases
["CVE-2026-106455"]
Ecosystems
["npm"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6ac6bfb72cdf04f656828ca0

Added to database: 10/07/2026, 21:55:03 UTC

Last enriched: 10/07/2026, 21:58:03 UTC

Last updated: 10/07/2026, 21:58:03 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses