Backstage 是一个用于构建开发者门户的开源框架。在版本 1.14.6 和 1.15.4 之前,@backstage/plugin-techdocs-node 包未能充分验证 TechDocs Markdown 扩展配置。具有注册或修改文档来源权限的已认证用户可能触发 TechDocs 构建过程,使其访问超出预期文档边界的资源,从而潜在地暴露后端托管数据或内部网络资源。该问题已在版本 1.14.6 和 1.15.4 中得到修复,前提是同时使用 pymdown-extensions 10.21.3 或更高版本(
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | < 1.50.5 | - |
|
| @backstage | plugin-techdocs-node | < 1.14.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106558 | 8.8 HIGH | Backstage: Improper validation of TechDocs MkDocs configuration |
| CVE-2026-106510 | 7.7 HIGH | Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml |
| CVE-2026-106556 | 7.7 HIGH | Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization |
| CVE-2026-106560 | 7.1 HIGH | Backstage: Improper repository path validation in a Scaffolder backend module |
| CVE-2026-106559 | 6.3 MEDIUM | Backstage: Improper input validation in Confluence to Markdown scaffolder module |
| CVE-2026-106563 | 5.3 MEDIUM | Backstage: Improper entity validation in deprecated Kubernetes services endpoint |
| CVE-2026-106561 | 5.0 MEDIUM | Backstage: Sensitive information disclosure in Kubernetes resource queries |
| CVE-2026-106562 | 4.3 MEDIUM | Backstage: Incorrect authorization in search engine permission filtering |
No comments yet