Remote command execution In @backstage/plugin-techdocs-node
Description
Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml
Impact
An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built.
Patches
Patched in @backstage/plugin-techdocs-node, version 1.15.4.
Workarounds
If you cannot upgrade immediately:
Switch to techdocs.builder: external to isolate TechDocs builds in a container.
Restrict who can register catalog entities with TechDocs annotations.
Audit existing catalog entities for suspicious markdown_extensions values in their mkdocs.yml files.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.15.4 |
Aliases
References