Backstage 是一个用于构建开发者门户的开源框架。在 1.14.6 版本之前, 包存在远程代码执行漏洞,该漏洞可通过在 TechDocs 的 mkdocs.yml 中构造恶意 来触发。具有注册目录实体权限的认证用户可以提交恶意的 mkdocs.yml 文件,当文档构建时,将在 TechDocs 构建主机上导致任意操作系统命令执行。此问题已在 1.14.6 和 1.15.4 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | < 1.50.5 | - |
|
| @backstage | plugin-techdocs-node | < 1.14.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106558 | 8.8 HIGH | Backstage: Improper validation of TechDocs MkDocs configuration |
| CVE-2026-106556 | 7.7 HIGH | Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization |
| CVE-2026-106557 | 7.7 HIGH | Backstage: Improper input validation in TechDocs Markdown extension configuration |
| CVE-2026-106560 | 7.1 HIGH | Backstage: Improper repository path validation in a Scaffolder backend module |
| CVE-2026-106559 | 6.3 MEDIUM | Backstage: Improper input validation in Confluence to Markdown scaffolder module |
| CVE-2026-106563 | 5.3 MEDIUM | Backstage: Improper entity validation in deprecated Kubernetes services endpoint |
| CVE-2026-106561 | 5.0 MEDIUM | Backstage: Sensitive information disclosure in Kubernetes resource queries |
| CVE-2026-106562 | 4.3 MEDIUM | Backstage: Incorrect authorization in search engine permission filtering |
No comments yet