Bug 2547504 (CVE-2026-106556) - CVE-2026-106556 plugin-techdocs-node: plugin-techdocs-node: arbitrary command execution via configuration sanitization bypass
Summary: CVE-2026-106556 plugin-techdocs-node: plugin-techdocs-node: arbitrary command...
Keywords:
Status: NEW
Alias: CVE-2026-106556
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-07 14:53 UTC by OSIDB Bzimport
Modified: 2026-10-08 05:36 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-07 14:53:39 UTC
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configuration bypass in techdocs mkdocs.yml sanitization. Insufficient validation of MkDocs configuration during TechDocs generation could allow an authenticated user who can register or modify documentation sources to execute arbitrary commands in the build environment. Impact is limited to resources accessible to the TechDocs backend or build container. This issue is fixed in versions 1.14.6 and 1.15.4.


Note You need to log in before you can comment on or make changes to this bug.