Vulnerability GHSA-f7v3-xhm6-w245
Summary
Backstage has improper input validation in TechDocs Markdown extension configuration
Details
Impact
An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4.
Adopters must also use pymdown-extensions version 10.21.3 or newer, normally through mkdocs-techdocs-core version 1.7.0 or newer. @backstage/plugin-techdocs-node does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized.
Workarounds
- Generate TechDocs only from trusted repositories with reviewed MkDocs configuration.
- Use isolated build environments with restricted filesystem access and network egress.
- Prefer externally generated TechDocs with appropriately sandboxed CI.
Related Vulnerabilities
Other vulnerabilities affecting the same packages