Vulnerability GHSA-8w7q-29mw-gf5c

High Risk
HIGH RISK
CVSS Score: 7.7
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 07, 2026 at 04:23 PM UTC
Backstage: Improper validation of MkDocs theme configuration in TechDocs
0.0.0-nightly-20220305022735 - 1.15.3
0.0.0-nightly-20220305022735 - 1.15.3

Summary

Backstage: Improper validation of MkDocs theme configuration in TechDocs

Details

Impact

When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process.

Patches

Patched in @backstage/plugin-techdocs-node version 1.15.4

Workarounds

  • Configure TechDocs with techdocs.generator.runIn: 'docker' instead of 'local' to provide container isolation, though this does not fully mitigate the risk.
  • Restrict write access to repositories registered in the Backstage catalog to trusted users.

Timeline

Published
2 hours ago
October 07, 2026 at 04:23 PM UTC
Fixed (1.15.4)
1 month ago
August 28, 2026 at 08:22 AM UTC
Last Modified
2 hours ago
October 07, 2026 at 04:30 PM UTC