Vulnerability DatabaseCVE-2026-106557

CVE-2026-106557: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-106557 is an improper input validation vulnerability in Backstage's @backstage/plugin-techdocs-node package affecting TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing sensitive backend-host data or internal network resources. The vulnerability affects @backstage/plugin-techdocs-node versions prior to 1.14.6 and versions 1.15.0–1.15.3, as well as Backstage versions prior to 1.50.5 and 1.51.0-next.0 through 1.54.5. It was published on October 7, 2026, with a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory).

Technical details

The root cause is insufficient validation of TechDocs MkDocs configuration, specifically the pymdownx.snippets Markdown extension options (CWE-22: Path Traversal; CWE-918: Server-Side Request Forgery). The sanitizeMkdocsYml function in mkdocsPatchers.ts failed to strip dangerous configuration keys such as base_path, restrict_base_path: false, and url_download: true from pymdownx.snippets extension entries in mkdocs.yml. An attacker could craft a malicious mkdocs.yml with these options set to arbitrary paths or URLs, causing the TechDocs build process to read files from outside the documentation directory or make outbound HTTP requests to internal network resources. The fix constrains all pymdownx.snippets and pymdownx.snippets:SnippetExtension configuration to empty objects, stripping any user-supplied options (GitHub Commit 017ace5, GitHub Commit 2d9de4c).

Impact

Successful exploitation allows an authenticated attacker to exfiltrate sensitive files from the backend host's filesystem (e.g., credentials, configuration files, secrets) or probe internal network services via SSRF during TechDocs build execution. The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component itself to the underlying host and internal network. Integrity and availability are not directly impacted, but confidentiality is rated High due to the potential for broad data exposure (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the advisory date. The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not automatable, as it requires an authenticated user with the ability to register or modify documentation sources. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Gain authenticated access: Obtain a Backstage account with permissions to register or modify documentation sources (e.g., a developer or contributor role).
  2. Craft malicious mkdocs.yml: Create or modify a mkdocs.yml file in a documentation repository to include a pymdownx.snippets extension with dangerous options, such as:
    markdown_extensions:
      - pymdownx.snippets:
          base_path: /
          restrict_base_path: false
          url_download: true
  3. Register the documentation source: Register the repository containing the malicious mkdocs.yml as a TechDocs documentation source in Backstage.
  4. Trigger a TechDocs build: Initiate a documentation build (manually or via CI/CD integration), causing the TechDocs generator to process the malicious configuration.
  5. Exploit path traversal or SSRF: The pymdownx.snippets extension, using the attacker-controlled base_path: /, will include files from arbitrary filesystem paths (e.g., /etc/passwd, cloud metadata credentials). With url_download: true, it can also fetch internal network URLs (e.g., http://169.254.169.254/latest/meta-data/).
  6. Retrieve exfiltrated data: The included file contents are rendered into the generated documentation output, which the attacker can then read via the Backstage TechDocs UI (GitHub Advisory, GitHub Commit 017ace5).

Indicators of compromise

  • File System: Presence of mkdocs.yml files containing pymdownx.snippets with keys such as base_path, restrict_base_path: false, or url_download: true in documentation repositories.
  • Logs: TechDocs build logs containing warnings about stripped pymdownx.snippets configuration (post-patch) or, on unpatched systems, absence of such warnings despite suspicious extension configs; unexpected file inclusion errors referencing paths outside the docs directory.
  • Network: Outbound HTTP requests from the TechDocs build environment to internal metadata endpoints (e.g., 169.254.169.254) or unexpected internal hosts during documentation generation.
  • Process: TechDocs/MkDocs build processes accessing files outside the expected documentation directory (e.g., /etc/, /var/, cloud credential paths) as observed via filesystem audit logs or container runtime monitoring.

Mitigation and workarounds

Upgrade @backstage/plugin-techdocs-node to version 1.14.6 or 1.15.4, and ensure pymdown-extensions 10.21.3 or later is used (typically via mkdocs-techdocs-core 1.7.0 or later). For Backstage as a whole, upgrade to version 1.50.5 or 1.54.6 (Backstage v1.50.5, Backstage v1.54.6). If immediate upgrade is not possible, apply these workarounds: (1) generate TechDocs only from trusted repositories with reviewed MkDocs configurations; (2) use isolated build environments with restricted filesystem access and network egress; (3) prefer externally generated TechDocs with appropriately sandboxed CI pipelines (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-106557HIGH7.7
  • JavaScript logoJavaScript
  • @backstage/plugin-techdocs-node
NoYesOct 07, 2026
CVE-2026-106108MEDIUM5.6
  • JavaScript logoJavaScript
  • @quasar/app-vite
NoYesOct 07, 2026
CVE-2026-106563MEDIUM5.3
  • JavaScript logoJavaScript
  • @backstage/plugin-kubernetes-backend
NoYesOct 07, 2026
CVE-2026-106561MEDIUM5
  • JavaScript logoJavaScript
  • @backstage/plugin-kubernetes-backend
NoYesOct 07, 2026
CVE-2026-106562MEDIUM4.3
  • JavaScript logoJavaScript
  • @backstage/plugin-search-backend
NoYesOct 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management