Vulnerabilities

Summary — last 7 days

New vulnerabilities2,853▼ 343 vs. last week
Critical / high1,376▼ 50 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)298▼ 212 vs. last week
–

7 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedHigh (7.7)——Backstage Plugin Techdocs NodeAI10/6/202610/6/2026
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a…
ReceivedMedium (5.3)——Backstage Plugin Techdocs NodeAI10/6/202610/6/2026
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving…
ReceivedMedium (5.3)——Backstage Plugin Techdocs NodeAI10/6/202610/6/2026
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to…
ReceivedHigh (7.7)——Backstage Plugin Techdocs NodeAI10/6/202610/6/2026
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs…
ReceivedHigh (7.7)——Backstage Plugin Techdocs NodeAI10/6/202610/6/2026
Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a…
Awaiting AnalysisHigh (8.8)1.2%—Backstage Plugin-techdocs-nodeAI9/16/20269/30/2026
Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can register or modify a TechDocs source. Unsafe Python YAML tags, markdown_extensions names…
ModifiedCritical (9.8)0.95%—Linuxfoundation Backstage Plugin-techdocs-node3/7/20267/15/2026
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process.…
Orbitaley — Vulnerabilities