{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abackstagebackstage/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:backstage:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-106509"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-techdocs-node (\u003c 1.15.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eBackstage, an open platform for building developer portals, is vulnerable to a remote code execution (RCE) flaw in the \u003ccode\u003e@backstage/plugin-techdocs-node\u003c/code\u003e package. Tracked as CVE-2026-106509, the issue stems from improper validation of configuration values within the \u003ccode\u003emkdocs.yml\u003c/code\u003e file used by the TechDocs plugin.\u003c/p\u003e\n\u003cp\u003eWhen TechDocs is configured to perform documentation builds locally or within a container environment, an attacker with repository write access can inject malicious configuration directives. These directives are processed during the documentation build stage, leading to the execution of arbitrary commands on the build infrastructure. This vulnerability poses a high risk to organizations that permit documentation builds from untrusted or compromised repository contributors. The vulnerability was remediated in \u003ccode\u003e@backstage/plugin-techdocs-node\u003c/code\u003e version 1.15.4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains write access to a repository registered in the Backstage catalog.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the \u003ccode\u003emkdocs.yml\u003c/code\u003e file within the repository to include malicious configuration parameters.\u003c/li\u003e\n\u003cli\u003eThe TechDocs plugin triggers a build process for the documentation, either locally or within a container runner.\u003c/li\u003e\n\u003cli\u003eThe build process, facilitated by \u003ccode\u003eplugin-techdocs-node\u003c/code\u003e, parses the manipulated \u003ccode\u003emkdocs.yml\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to properly sanitize or validate the user-controlled configuration values.\u003c/li\u003e\n\u003cli\u003eThe underlying build engine executes the injected commands as part of the MkDocs build process.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution within the build environment (e.g., the Backstage host or the container instance).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary code on the infrastructure hosting the TechDocs build service. This can lead to credential theft, lateral movement within the build environment, or exposure of sensitive data processed by the documentation pipeline. Organizations using TechDocs in 'local' build mode are at the highest risk, though containerized deployments may also be compromised depending on the container runtime's isolation capabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of \u003ccode\u003e@backstage/plugin-techdocs-node\u003c/code\u003e to version 1.15.4 or later across all Backstage instances to address CVE-2026-106509. As a compensatory control for environments where immediate patching is not possible, modify the \u003ccode\u003etechdocs.generator.runIn\u003c/code\u003e configuration to use 'docker' instead of 'local' to enforce container-level isolation. Furthermore, strictly enforce repository write permissions to ensure only trusted users can modify documentation configurations and trigger builds.\u003c/p\u003e\n","date_modified":"2026-10-07T22:56:49Z","date_published":"2026-10-07T16:58:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/","summary":"An improper input validation vulnerability (CVE-2026-106509) in Backstage plugin-techdocs-node allows authenticated users to achieve arbitrary code execution via crafted mkdocs.yml files.","title":"Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:backstage:backstage:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}