Vulnerabilities
Summary — last 7 days
New vulnerabilities2,853▼ 343 vs. last week
Critical / high1,376▼ 50 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)298▼ 212 vs. last week
7 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | High (7.7) | — | — | Backstage Plugin Techdocs NodeAI | 10/6/2026 | 10/6/2026 | Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a… | |
| Received | Medium (5.3) | — | — | Backstage Plugin Techdocs NodeAI | 10/6/2026 | 10/6/2026 | Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving… | |
| Received | Medium (5.3) | — | — | Backstage Plugin Techdocs NodeAI | 10/6/2026 | 10/6/2026 | Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to… | |
| Received | High (7.7) | — | — | Backstage Plugin Techdocs NodeAI | 10/6/2026 | 10/6/2026 | Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs… | |
| Received | High (7.7) | — | — | Backstage Plugin Techdocs NodeAI | 10/6/2026 | 10/6/2026 | Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a… | |
| Awaiting Analysis | High (8.8) | 1.2% | — | Backstage Plugin-techdocs-nodeAI | 9/16/2026 | 9/30/2026 | Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can register or modify a TechDocs source. Unsafe Python YAML tags, markdown_extensions names… | |
| Modified | Critical (9.8) | 0.95% | — | Linuxfoundation Backstage Plugin-techdocs-node | 3/7/2026 | 7/15/2026 | Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process.… |