Server side template injection In @backstage/plugin-techdocs-node
Description
Backstage: Improper validation of MkDocs theme configuration in TechDocs
Impact
When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process.
Patches
Patched in @backstage/plugin-techdocs-node version 1.15.4
Workarounds
Configure TechDocs with techdocs.generator.runIn: 'docker' instead of 'local' to provide container isolation, though this does not fully mitigate the risk.
Restrict write access to repositories registered in the Backstage catalog to trusted users.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.15.4 |
Aliases
References