Vulnerability GHSA-f7v3-xhm6-w245

High Risk
HIGH RISK
CVSS Score: 7.7
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 07, 2026 at 04:22 PM UTC
Backstage has improper input validation in TechDocs Markdown extension configuration
0.0.0-nightly-20220305022735 - 1.15.3
0.0.0-nightly-20220305022735 - 1.15.3

Summary

Backstage has improper input validation in TechDocs Markdown extension configuration

Details

Impact

An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary. Depending on deployment configuration, this may expose sensitive backend-host data or internal network resources.

Patches

Patched in @backstage/plugin-techdocs-node version 1.15.4.

Adopters must also use pymdown-extensions version 10.21.3 or newer, normally through mkdocs-techdocs-core version 1.7.0 or newer. @backstage/plugin-techdocs-node does not control the Python dependencies used by the generator; with an older PyMdown release, snippets may remain vulnerable to file inclusion even after their configuration is sanitized.

Workarounds

  • Generate TechDocs only from trusted repositories with reviewed MkDocs configuration.
  • Use isolated build environments with restricted filesystem access and network egress.
  • Prefer externally generated TechDocs with appropriately sandboxed CI.

Timeline

Published
2 hours ago
October 07, 2026 at 04:22 PM UTC
Fixed (1.15.4)
1 month ago
August 28, 2026 at 08:22 AM UTC
Last Modified
2 hours ago
October 07, 2026 at 04:30 PM UTC