« Volver al listado

CVE-2026-106455

Estado: RecibidaAlta (7.7)—

Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a documentation build to retrieve and publish data from network locations reachable by the build environment. Exposure depends on deployment topology, build mode, and target endpoint protections. Modern cloud metadata services that require tokens or special headers are not directly accessible through the affected behavior. This issue is fixed in @backstage/plugin-techdocs-node versions 1.14.7 and 1.15.5.

CVSS

Probabilidad de explotación (EPSS)

FIRST aún no ha puntuado esta CVE (habitual en CVEs muy recientes o rechazadas).

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS con PR:L (requiere autenticación, ataque remoto). CWE-918 (SSRF) permite acceso a ubicaciones de red desde el entorno de compilación. La validación impropia de configuración de plugins en TechDocs permite a atacante autenticado causar que el build recupere datos desde ubicaciones de red

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-106455",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "backstage",
          "product": "backstage",
          "versions": [
            {
              "status": "affected",
              "version": ">= 0.71.1, < 1.50.6"
            },
            {
              "status": "affected",
              "version": ">= 1.51.0-next.0, < 1.54.8"
            }
          ]
        },
        {
          "vendor": "@backstage",
          "product": "plugin-techdocs-node",
          "versions": [
            {
              "status": "affected",
              "version": ">= 0.11.12, < 1.14.7"
            },
            {
              "status": "affected",
              "version": ">= 1.15.0, < 1.15.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-10-06T21:17:15.727",
  "references": [
    {
      "url": "https://github.com/backstage/backstage/commit/28aa82ae2815988721dd7bbf43cd69c431dcd71b",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/backstage/backstage/commit/9f76ea445088961f68c364764cc4b7734f368fc0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/backstage/backstage/releases/tag/v1.50.6",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/backstage/backstage/releases/tag/v1.54.8",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/backstage/backstage/releases/tag/v1.55.0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/backstage/backstage/security/advisories/GHSA-q38j-6vcm-2f5m",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Received",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a documentation build to retrieve and publish data from network locations reachable by the build environment. Exposure depends on deployment topology, build mode, and target endpoint protections. Modern cloud metadata services that require tokens or special headers are not directly accessible through the affected behavior. This issue is fixed in @backstage/plugin-techdocs-node versions 1.14.7 and 1.15.5."
    }
  ],
  "lastModified": "2026-10-06T21:17:15.727",
  "sourceIdentifier": "security-advisories@github.com"
}