« Back to list

Backstage

Backstage Plugin Techdocs Node: vulnerabilities and CVEs

Backstage Plugin Techdocs Node has 5 published vulnerabilities, 5 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months5
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-106509High (7.7)——Oct 6, 2026
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is…
CVE-2026-106508Medium (5.3)——Oct 6, 2026
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local…
CVE-2026-106507Medium (5.3)——Oct 6, 2026
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in…
CVE-2026-106505High (7.7)——Oct 6, 2026
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users…
CVE-2026-106455High (7.7)——Oct 6, 2026
Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services5
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter2
  4. T1090 Proxy1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Backstage