Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f7v3-xhm6-w245 | Backstage has improper input validation in TechDocs Markdown extension configuration |
Wed, 07 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing backend-host data or internal network resources. This issue is fixed in versions 1.14.6 and 1.15.4 when pymdown-extensions 10.21.3 or later is also used, normally through mkdocs-techdocs-core 1.7.0 or later. | |
| Title | Backstage: Improper input validation in TechDocs Markdown extension configuration | |
| Weaknesses | CWE-22 CWE-918 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T17:47:16.631Z
Reserved: 2026-10-06T20:31:59.017Z
Link: CVE-2026-106557
No data.
Status : Received
Published: 2026-10-07T17:16:50.900
Modified: 2026-10-07T17:16:50.900
Link: CVE-2026-106557
No data.
OpenCVE Enrichment
No data.
Github GHSA