
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-106557 is an improper input validation vulnerability in Backstage's @backstage/plugin-techdocs-node package affecting TechDocs Markdown extension configuration. An authenticated user who can register or modify documentation sources may cause a TechDocs build to access resources outside the intended documentation boundary, potentially exposing sensitive backend-host data or internal network resources. The vulnerability affects @backstage/plugin-techdocs-node versions prior to 1.14.6 and versions 1.15.0–1.15.3, as well as Backstage versions prior to 1.50.5 and 1.51.0-next.0 through 1.54.5. It was published on October 7, 2026, with a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory).
The root cause is insufficient validation of TechDocs MkDocs configuration, specifically the pymdownx.snippets Markdown extension options (CWE-22: Path Traversal; CWE-918: Server-Side Request Forgery). The sanitizeMkdocsYml function in mkdocsPatchers.ts failed to strip dangerous configuration keys such as base_path, restrict_base_path: false, and url_download: true from pymdownx.snippets extension entries in mkdocs.yml. An attacker could craft a malicious mkdocs.yml with these options set to arbitrary paths or URLs, causing the TechDocs build process to read files from outside the documentation directory or make outbound HTTP requests to internal network resources. The fix constrains all pymdownx.snippets and pymdownx.snippets:SnippetExtension configuration to empty objects, stripping any user-supplied options (GitHub Commit 017ace5, GitHub Commit 2d9de4c).
Successful exploitation allows an authenticated attacker to exfiltrate sensitive files from the backend host's filesystem (e.g., credentials, configuration files, secrets) or probe internal network services via SSRF during TechDocs build execution. The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component itself to the underlying host and internal network. Integrity and availability are not directly impacted, but confidentiality is rated High due to the potential for broad data exposure (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the advisory date. The NVD SSVC assessment indicates exploitation is currently "none" and the attack is not automatable, as it requires an authenticated user with the ability to register or modify documentation sources. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory, Feedly).
mkdocs.yml file in a documentation repository to include a pymdownx.snippets extension with dangerous options, such as:markdown_extensions:
- pymdownx.snippets:
base_path: /
restrict_base_path: false
url_download: truemkdocs.yml as a TechDocs documentation source in Backstage.pymdownx.snippets extension, using the attacker-controlled base_path: /, will include files from arbitrary filesystem paths (e.g., /etc/passwd, cloud metadata credentials). With url_download: true, it can also fetch internal network URLs (e.g., http://169.254.169.254/latest/meta-data/).mkdocs.yml files containing pymdownx.snippets with keys such as base_path, restrict_base_path: false, or url_download: true in documentation repositories.pymdownx.snippets configuration (post-patch) or, on unpatched systems, absence of such warnings despite suspicious extension configs; unexpected file inclusion errors referencing paths outside the docs directory.169.254.169.254) or unexpected internal hosts during documentation generation./etc/, /var/, cloud credential paths) as observed via filesystem audit logs or container runtime monitoring.Upgrade @backstage/plugin-techdocs-node to version 1.14.6 or 1.15.4, and ensure pymdown-extensions 10.21.3 or later is used (typically via mkdocs-techdocs-core 1.7.0 or later). For Backstage as a whole, upgrade to version 1.50.5 or 1.54.6 (Backstage v1.50.5, Backstage v1.54.6). If immediate upgrade is not possible, apply these workarounds: (1) generate TechDocs only from trusted repositories with reviewed MkDocs configurations; (2) use isolated build environments with restricted filesystem access and network egress; (3) prefer externally generated TechDocs with appropriately sandboxed CI pipelines (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."