PatchSiren cyber security CVE debrief
CVE-2026-106505 backstage CVE debrief
CVE-2026-106505: Backstage TechDocs backend vulnerable to MkDocs configuration sanitizer bypass. The vulnerability allows users with repository write access to execute arbitrary code on the TechDocs backend host during documentation generation. Defenders should assess exposure and prioritize remediation by upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, restricting repository write access, and reviewing incoming changes to MkDocs configuration files. This vulnerability has the potential to impact the confidentiality, integrity, and availability of affected systems.
- Vendor
- backstage
- Product
- @backstage/plugin-techdocs-node
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Backstage deployments using TechDocs should assess exposure and prioritize remediation. This includes upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, restricting repository write access, and reviewing incoming changes to MkDocs configuration files. Additionally, defenders should verify @backstage/plugin-techdocs-node version and monitor for suspicious activity on TechDocs backend host.
Why it matters
CVE-2026-106505 allows users with repository write access to bypass MkDocs configuration sanitizer and execute arbitrary code on TechDocs backend host. Defenders should prioritize upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, restrict repository write access, and review incoming changes to MkDocs configuration files.
- Potential code execution on TechDocs backend host
- Possible compromise of TechDocs backend host
- Need for restricted repository write access
- Verification of @backstage/plugin-techdocs-node version
Technical summary
Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer and execute arbitrary code on the TechDocs backend host during documentation generation. This vulnerability is caused by a bypass of the MkDocs configuration sanitizer in the TechDocs backend. The vulnerability has the potential to impact the confidentiality, integrity, and availability of affected systems. Defenders should prioritize upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, and restrict repository write access to trusted parties.
Defensive priority
Defenders should prioritize upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, and restrict repository write access to trusted parties.
Recommended defensive actions
- Upgrade @backstage/plugin-techdocs-node to version 1.15.4 or later
- Restrict repository write access to trusted parties
- Review incoming changes to MkDocs configuration files as part of code review process
- Use Docker mode with restricted access
- Verify @backstage/plugin-techdocs-node version
- Monitor for suspicious activity on TechDocs backend host
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and source item provide details on the vulnerability, including its impact, patches, and workarounds. However, the CVSS score and severity are not provided. The vulnerability is caused by a bypass of the MkDocs configuration sanitizer in the TechDocs backend, which allows users with repository write access to execute arbitrary code. The CVE record and source item also provide information on the affected products and versions, as well as the patches and workarounds available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106505 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106505
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106505 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106505
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-p75x-jh7p-ppcx.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/security/advisories/GHSA-p75x-jh7p-ppcx
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/a7d995f11a5d27f0efbdbe8bb6c21b06988c79c9
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/ef92d3d2b76046205c580e7152956514c15640db
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.50.5
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.54.6
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.