<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Plugin-Techdocs-Node (&lt; 1.15.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/plugin-techdocs-node--1.15.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:58:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/plugin-techdocs-node--1.15.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/</link><pubDate>Wed, 07 Oct 2026 16:58:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/</guid><description>An improper input validation vulnerability (CVE-2026-106509) in Backstage plugin-techdocs-node allows authenticated users to achieve arbitrary code execution via crafted mkdocs.yml files.</description><content:encoded><![CDATA[<p>Backstage, an open platform for building developer portals, is vulnerable to a remote code execution (RCE) flaw in the <code>@backstage/plugin-techdocs-node</code> package. Tracked as CVE-2026-106509, the issue stems from improper validation of configuration values within the <code>mkdocs.yml</code> file used by the TechDocs plugin.</p>
<p>When TechDocs is configured to perform documentation builds locally or within a container environment, an attacker with repository write access can inject malicious configuration directives. These directives are processed during the documentation build stage, leading to the execution of arbitrary commands on the build infrastructure. This vulnerability poses a high risk to organizations that permit documentation builds from untrusted or compromised repository contributors. The vulnerability was remediated in <code>@backstage/plugin-techdocs-node</code> version 1.15.4.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains write access to a repository registered in the Backstage catalog.</li>
<li>Attacker modifies the <code>mkdocs.yml</code> file within the repository to include malicious configuration parameters.</li>
<li>The TechDocs plugin triggers a build process for the documentation, either locally or within a container runner.</li>
<li>The build process, facilitated by <code>plugin-techdocs-node</code>, parses the manipulated <code>mkdocs.yml</code> file.</li>
<li>The plugin fails to properly sanitize or validate the user-controlled configuration values.</li>
<li>The underlying build engine executes the injected commands as part of the MkDocs build process.</li>
<li>Attacker achieves remote code execution within the build environment (e.g., the Backstage host or the container instance).</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to execute arbitrary code on the infrastructure hosting the TechDocs build service. This can lead to credential theft, lateral movement within the build environment, or exposure of sensitive data processed by the documentation pipeline. Organizations using TechDocs in 'local' build mode are at the highest risk, though containerized deployments may also be compromised depending on the container runtime's isolation capabilities.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of <code>@backstage/plugin-techdocs-node</code> to version 1.15.4 or later across all Backstage instances to address CVE-2026-106509. As a compensatory control for environments where immediate patching is not possible, modify the <code>techdocs.generator.runIn</code> configuration to use 'docker' instead of 'local' to enforce container-level isolation. Furthermore, strictly enforce repository write permissions to ensure only trusted users can modify documentation configurations and trigger builds.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>supply-chain</category></item></channel></rss>