Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration
An improper input validation vulnerability (CVE-2026-106509) in Backstage plugin-techdocs-node allows authenticated users to achieve arbitrary code execution via crafted mkdocs.yml files.
CVE search metadata
CVE search record: CVE-2026-106509. Severity: high. CVSS: 7.7. KEV: no. Product: plugin-techdocs-node (< 1.15.4). Brief: Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration. Brief link: https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/
What's new
- 1. added coverage for plugin-techdocs-node (< 1.15.4) Oct 7, 22:56 via ghsa
Backstage, an open platform for building developer portals, is vulnerable to a remote code execution (RCE) flaw in the @backstage/plugin-techdocs-node package. Tracked as CVE-2026-106509, the issue stems from improper validation of configuration values within the mkdocs.yml file used by the TechDocs plugin.
When TechDocs is configured to perform documentation builds locally or within a container environment, an attacker with repository write access can inject malicious configuration directives. These directives are processed during the documentation build stage, leading to the execution of arbitrary commands on the build infrastructure. This vulnerability poses a high risk to organizations that permit documentation builds from untrusted or compromised repository contributors. The vulnerability was remediated in @backstage/plugin-techdocs-node version 1.15.4.
Attack Chain
- Attacker gains write access to a repository registered in the Backstage catalog.
- Attacker modifies the
mkdocs.ymlfile within the repository to include malicious configuration parameters. - The TechDocs plugin triggers a build process for the documentation, either locally or within a container runner.
- The build process, facilitated by
plugin-techdocs-node, parses the manipulatedmkdocs.ymlfile. - The plugin fails to properly sanitize or validate the user-controlled configuration values.
- The underlying build engine executes the injected commands as part of the MkDocs build process.
- Attacker achieves remote code execution within the build environment (e.g., the Backstage host or the container instance).
Impact
Successful exploitation allows an attacker to execute arbitrary code on the infrastructure hosting the TechDocs build service. This can lead to credential theft, lateral movement within the build environment, or exposure of sensitive data processed by the documentation pipeline. Organizations using TechDocs in 'local' build mode are at the highest risk, though containerized deployments may also be compromised depending on the container runtime's isolation capabilities.
Recommendation
Prioritize the upgrade of @backstage/plugin-techdocs-node to version 1.15.4 or later across all Backstage instances to address CVE-2026-106509. As a compensatory control for environments where immediate patching is not possible, modify the techdocs.generator.runIn configuration to use 'docker' instead of 'local' to enforce container-level isolation. Furthermore, strictly enforce repository write permissions to ensure only trusted users can modify documentation configurations and trigger builds.
Immediate actions
Upgrade @backstage/plugin-techdocs-node to 1.15.4 or later.
Mitigations
Set techdocs.generator.runIn to 'docker' and restrict repository write access.
CVE-2026-106509