Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4. | |
| Title | Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend | |
| Weaknesses | CWE-426 CWE-436 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T21:43:08.370Z
Reserved: 2026-10-06T18:46:47.766Z
Link: CVE-2026-106505
No data.
Status : Received
Published: 2026-10-06T22:17:05.837
Modified: 2026-10-06T22:17:05.837
Link: CVE-2026-106505
No data.
OpenCVE Enrichment
No data.