Lack of data validation In @backstage/plugin-techdocs-node
Description
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
Impact
Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation.
Patches
Patched in@backstage/plugin-techdocs-node version 1.15.4
Workarounds
If you cannot upgrade immediately:
Use Docker mode with restricted access: Configure TechDocs with runIn: docker instead of runIn: local. This provides container isolation, though it does not fully mitigate the risk.
Limit repository write access to trusted parties, since exploitation requires the ability to commit files to a repository with TechDocs enabled.
Review incoming changes to MkDocs configuration files as part of your code review process.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.15.4 |
Aliases
References