CVE-2026-106558

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,8
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can register or influence an SCM-backed documentation source may bypass TechDocs sanitization and cause Python objects to be imported and instantiated in the generator runtime, leading to arbitrary code execution. Earlier fixes in versions 1.14.6 and 1.15.4 did not fully address the supported mapping representation of markdown_extensions. Impact is greatest when documentation generation runs with backend credentials, filesystem access, or internal network access. This issue is fixed in versions 1.14.8, 1.15.6, and 2.0.1.

502

Deserialization of Untrusted Data

Draft
Common Consequences
Security Scopes Affected:
Integrity Availability Other
Potential Impacts:
Modify Application Data Unexpected State Dos: Resource Consumption (Cpu) Varies By Context
Applicable Platforms
Languages: Java, Ruby, PHP, Python, JavaScript
Technologies: Not Technology-Specific, ICS/OT, AI/ML
View CWE Details
https://github.com/backstage/backstage/commit/32723a0fe4e12ed80535fc65d5331765c…
https://github.com/backstage/backstage/commit/944edb51c8524d3664b18f2d57ba101b1…
https://github.com/backstage/backstage/commit/f18e9abcc6051491862b15e4fc60e69f8…
https://github.com/backstage/backstage/releases/tag/v1.50.7
https://github.com/backstage/backstage/releases/tag/v1.54.9
https://github.com/backstage/backstage/releases/tag/v1.55.2
https://github.com/backstage/backstage/security/advisories/GHSA-qmw3-745m-w99g