Vulnerability GHSA-p75x-jh7p-ppcx

High Risk
HIGH RISK
CVSS Score: 7.7
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 07, 2026 at 04:23 PM UTC
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
0.0.0-nightly-20220305022735 - 1.15.3
0.0.0-nightly-20220305022735 - 1.15.3

Summary

Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend

Details

Impact

Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation.

Patches

Patched in@backstage/plugin-techdocs-node version 1.15.4

Workarounds

If you cannot upgrade immediately:

  • Use Docker mode with restricted access: Configure TechDocs with runIn: docker instead of runIn: local. This provides container isolation, though it does not fully mitigate the risk.
  • Limit repository write access to trusted parties, since exploitation requires the ability to commit files to a repository with TechDocs enabled.
  • Review incoming changes to MkDocs configuration files as part of your code review process.

Timeline

Published
2 hours ago
October 07, 2026 at 04:23 PM UTC
Fixed (1.15.4)
1 month ago
August 28, 2026 at 08:22 AM UTC
Last Modified
2 hours ago
October 07, 2026 at 04:30 PM UTC