CVE-2026-106510
HIGH
7,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: low
Availability: low
Description
AI Translation Available
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built. This issue is fixed in versions 1.14.6 and 1.15.4.
183
Permissive List of Allowed Inputs
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Other
Potential Impacts:
Execute Unauthorized Code Or Commands
Alter Execution Logic
Dos: Crash, Exit, Or Restart
Other
Read Application Data
Applicable Platforms
Languages:
Java, PHP, Interpreted
https://github.com/backstage/backstage/commit/02cd7cdbb18b687446277b5602adaee7f…
https://github.com/backstage/backstage/commit/a900a9953c8f7ad3ba1906d1d257725a9…
https://github.com/backstage/backstage/releases/tag/v1.50.5
https://github.com/backstage/backstage/releases/tag/v1.54.6
https://github.com/backstage/backstage/security/advisories/GHSA-4488-j8vj-vqqv