PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106455 backstage CVE debrief

CVE-2026-106455 debrief: Improper validation of MkDocs plugin configuration in TechDocs allows authenticated attackers to cause documentation builds to retrieve and publish data from reachable network locations. Exposure depends on deployment topology, build mode, and target endpoint protections. Upgrade `@backstage/plugin-techdocs-node` to patched versions: `1.14.7` or later for `1.14.x`, `1.15.5` or later for `1.15.x`, and `2.0.0` or later for the mainline.

Vendor
backstage
Product
@backstage/plugin-techdocs-node
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Backstage deployments, specifically those using TechDocs and MkDocs plugins, should assess exposure based on their deployment topology, build mode, and endpoint protections. They should prioritize upgrading to patched versions of `@backstage/plugin-techdocs-node` and review plugin configurations to prevent unauthorized data retrieval.

Why it matters

CVE-2026-106455 allows authenticated attackers to cause documentation builds to retrieve and publish data from reachable network locations. Defenders should prioritize patching, review plugin configurations, and assess exposure based on deployment topology.

  • Potential unauthorized data retrieval from network locations reachable by the build environment
  • Need to review and update MkDocs plugin configurations to prevent exploitation
  • Priority on upgrading `@backstage/plugin-techdocs-node` to patched versions
  • Verification of deployment topology and build mode to assess exposure

Technical summary

CVE-2026-106455 involves improper validation of MkDocs plugin configurations in TechDocs, allowing authenticated attackers with control over a TechDocs source repository to cause documentation builds to retrieve and publish data from network locations reachable by the build environment. The vulnerability's impact depends on the deployment topology, build mode, and protections of target endpoints. Notably, modern cloud metadata services requiring tokens or special headers are not directly accessible through the affected behavior. Patches are available in `@backstage/plugin-techdocs-node` versions `1.14.7`, `1.15.5`, and `2.0.0` or later, which remove MkDocs plugins outside the built-in allowlist. Users can also configure `techdocs.generator.mkdocs.dangerouslyAllowAdditionalPlugins` to retain additional plugins after review.

Defensive priority

Defenders should prioritize upgrading `@backstage/plugin-techdocs-node` to patched versions and review MkDocs plugin configurations to prevent unauthorized data retrieval.

Recommended defensive actions

  • Upgrade `@backstage/plugin-techdocs-node` to `1.14.7` or later for `1.14.x` release line
  • Upgrade `@backstage/plugin-techdocs-node` to `1.15.5` or later for `1.15.x` release line
  • Upgrade `@backstage/plugin-techdocs-node` to `2.0.0` or later for the current mainline
  • Review and configure `techdocs.generator.mkdocs.dangerouslyAllowAdditionalPlugins` for additional plugins
  • Verify deployment topology and build mode to assess exposure
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The source corpus provides details on the vulnerability and patches but does not specify exploitation or specific victims. Exposure depends on deployment topology and configurations. Defenders should verify configurations, review plugin allowlists, and assess build environment protections to understand potential impact. Additional evidence gathering may be required to confirm affected systems and validate patches.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106455 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106455

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106455 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106455

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Backstage: Improper validation of MkDocs plugin configuration in TechDocs

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-q38j-6vcm-2f5m.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/security/advisories/GHSA-q38j-6vcm-2f5m

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/commit/28aa82ae2815988721dd7bbf43cd69c431dcd71b

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/commit/9f76ea445088961f68c364764cc4b7734f368fc0

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/releases/tag/v1.50.6

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/releases/tag/v1.54.8

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/releases/tag/v1.55.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.