Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p75x-jh7p-ppcx | Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend |
Fri, 09 Oct 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation backstage Linuxfoundation backstage Plugin-techdocs-node |
|
| CPEs | cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:backstage:1.51.0:-:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:backstage:1.51.0:next0:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:backstage:1.51.0:next1:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:backstage:1.51.0:next2:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:backstage:1.51.0:next3:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:backstage_plugin-techdocs-node:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linuxfoundation
Linuxfoundation backstage Linuxfoundation backstage Plugin-techdocs-node |
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Backstage
Backstage backstage Backstage plugin-techdocs-node |
|
| Vendors & Products |
Backstage
Backstage backstage Backstage plugin-techdocs-node |
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 06 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4. | |
| Title | Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend | |
| Weaknesses | CWE-426 CWE-436 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T16:14:14.192Z
Reserved: 2026-10-06T18:46:47.766Z
Link: CVE-2026-106505
Updated: 2026-10-07T16:13:39.159Z
Status : Analyzed
Published: 2026-10-06T22:17:05.837
Modified: 2026-10-09T17:58:21.970
Link: CVE-2026-106505
OpenCVE Enrichment
Updated: 2026-10-09T08:31:03Z
Github GHSA