Vulnerability GHSA-8w7q-29mw-gf5c
High Risk
HIGH RISK
CVSS Score: 7.7
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 07, 2026 at 04:23 PM UTC
Backstage: Improper validation of MkDocs theme configuration in TechDocs
0.0.0-nightly-20220305022735 - 1.15.3
0.0.0-nightly-20220305022735 - 1.15.3
Summary
Backstage: Improper validation of MkDocs theme configuration in TechDocs
Details
Impact
When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4
Workarounds
- Configure TechDocs with
techdocs.generator.runIn: 'docker'instead of'local'to provide container isolation, though this does not fully mitigate the risk. - Restrict write access to repositories registered in the Backstage catalog to trusted users.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 hours ago
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
0.0.0-nightly-20220305022735 - 1.15.3 GHSA-p75x-jh7p-ppcx
0.0.0-nightly-20220305022735 - 1.15.3 GHSA-p75x-jh7p-ppcx
Medium Risk
2 hours ago
Backstage has potential file exposure through local TechDocs publisher
0.0.0-nightly-20220305022735 - 1.15.3 GHSA-cm77-ch27-6w6v
0.0.0-nightly-20220305022735 - 1.15.3 GHSA-cm77-ch27-6w6v
High Risk
2 hours ago
Backstage has improper input validation in TechDocs Markdown extension configuration
0.0.0-nightly-20220305022735 - 1.15.3 GHSA-f7v3-xhm6-w245
0.0.0-nightly-20220305022735 - 1.15.3 GHSA-f7v3-xhm6-w245
High Risk
7 months ago
TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution
0.0.0-nightly-20220305022735 - 1.14.3-next.1 GHSA-928r-fm4v-mvrw
0.0.0-nightly-20220305022735 - 1.14.3-next.1 GHSA-928r-fm4v-mvrw
High Risk
8 months ago
@backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks
0.0.0-nightly-20220305022735 - 1.13.11-next.0 and 1.14.0 - 1.14.1-next.0 GHSA-6jr7-99pf-8vgf
0.0.0-nightly-20220305022735 - 1.13.11-next.0 and 1.14.0 - 1.14.1-next.0 GHSA-6jr7-99pf-8vgf
Impacted packages
Timeline
Published
2 hours ago
October 07, 2026 at 04:23 PM UTC
Fixed (1.15.4)
1 month ago
August 28, 2026 at 08:22 AM UTC
Last Modified
2 hours ago
October 07, 2026 at 04:30 PM UTC