CVE-2026-106505
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-426
Ruta de búsqueda no confiable
Fecha de publicación:
06/10/2026
Última modificación:
06/10/2026
Descripción
*** Pendiente de traducción *** Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4.
Impacto
Puntuación base 3.x
7.70
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://github.com/backstage/backstage/commit/a7d995f11a5d27f0efbdbe8bb6c21b06988c79c9
- https://github.com/backstage/backstage/commit/ef92d3d2b76046205c580e7152956514c15640db
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/backstage/backstage/security/advisories/GHSA-p75x-jh7p-ppcx


