CVE-2026-106509

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,7
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: low
Availability: low

Description

AI Translation Available

Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process. This issue is fixed in versions 1.14.6 and 1.15.4.

94

Improper Control of Generation of Code ('Code Injection')

Draft
Common Consequences
Security Scopes Affected:
Access Control Integrity Confidentiality Availability Non-Repudiation
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands Hide Activities
Applicable Platforms
Languages: Interpreted
Technologies: AI/ML
View CWE Details
1336

Improper Neutralization of Special Elements Used in a Template Engine

Incomplete
Common Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages: Java, PHP, Python, JavaScript, Interpreted
Technologies: Not Technology-Specific, AI/ML, Client Server
View CWE Details
https://github.com/backstage/backstage/commit/02cd7cdbb18b687446277b5602adaee7f…
https://github.com/backstage/backstage/commit/a900a9953c8f7ad3ba1906d1d257725a9…
https://github.com/backstage/backstage/releases/tag/v1.50.5
https://github.com/backstage/backstage/releases/tag/v1.54.6
https://github.com/backstage/backstage/security/advisories/GHSA-8w7q-29mw-gf5c