PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106505 backstage CVE debrief

CVE-2026-106505: Backstage TechDocs backend vulnerable to MkDocs configuration sanitizer bypass. The vulnerability allows users with repository write access to execute arbitrary code on the TechDocs backend host during documentation generation. Defenders should assess exposure and prioritize remediation by upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, restricting repository write access, and reviewing incoming changes to MkDocs configuration files. This vulnerability has the potential to impact the confidentiality, integrity, and availability of affected systems.

Vendor
backstage
Product
@backstage/plugin-techdocs-node
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Backstage deployments using TechDocs should assess exposure and prioritize remediation. This includes upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, restricting repository write access, and reviewing incoming changes to MkDocs configuration files. Additionally, defenders should verify @backstage/plugin-techdocs-node version and monitor for suspicious activity on TechDocs backend host.

Why it matters

CVE-2026-106505 allows users with repository write access to bypass MkDocs configuration sanitizer and execute arbitrary code on TechDocs backend host. Defenders should prioritize upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, restrict repository write access, and review incoming changes to MkDocs configuration files.

  • Potential code execution on TechDocs backend host
  • Possible compromise of TechDocs backend host
  • Need for restricted repository write access
  • Verification of @backstage/plugin-techdocs-node version

Technical summary

Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer and execute arbitrary code on the TechDocs backend host during documentation generation. This vulnerability is caused by a bypass of the MkDocs configuration sanitizer in the TechDocs backend. The vulnerability has the potential to impact the confidentiality, integrity, and availability of affected systems. Defenders should prioritize upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, and restrict repository write access to trusted parties.

Defensive priority

Defenders should prioritize upgrading @backstage/plugin-techdocs-node to version 1.15.4 or later, and restrict repository write access to trusted parties.

Recommended defensive actions

  • Upgrade @backstage/plugin-techdocs-node to version 1.15.4 or later
  • Restrict repository write access to trusted parties
  • Review incoming changes to MkDocs configuration files as part of code review process
  • Use Docker mode with restricted access
  • Verify @backstage/plugin-techdocs-node version
  • Monitor for suspicious activity on TechDocs backend host
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and source item provide details on the vulnerability, including its impact, patches, and workarounds. However, the CVSS score and severity are not provided. The vulnerability is caused by a bypass of the MkDocs configuration sanitizer in the TechDocs backend, which allows users with repository write access to execute arbitrary code. The CVE record and source item also provide information on the affected products and versions, as well as the patches and workarounds available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106505 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106505

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106505 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106505

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-p75x-jh7p-ppcx.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/security/advisories/GHSA-p75x-jh7p-ppcx

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/commit/a7d995f11a5d27f0efbdbe8bb6c21b06988c79c9

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/commit/ef92d3d2b76046205c580e7152956514c15640db

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/releases/tag/v1.50.5

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/releases/tag/v1.54.6

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.