---
id: CVE-2026-106455
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. From 0.11.12
  until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is
  affected by improper validation of mkdocs plugin configuration in techdocs. An
  authentica…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: backstage
product: backstage
affected:
  - 'backstage >= 0.71.1, < 1.50.6'
  - 'backstage >= 1.51.0-next.0, < 1.54.8'
  - 'plugin-techdocs-node >= 0.11.12, < 1.14.7'
  - 'plugin-techdocs-node >= 1.15.0, < 1.15.5'
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:15.727'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106455'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/28aa82ae2815988721dd7bbf43cd69c431dcd71b
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/commit/9f76ea445088961f68c364764cc4b7734f368fc0
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.50.6'
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.54.8'
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.55.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-q38j-6vcm-2f5m
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T21:20:28.980Z'
---

## Overview

Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authenticated attacker with control over a TechDocs source repository could cause a documentation build to retrieve and publish data from network locations reachable by the build environment. Exposure depends on deployment topology, build mode, and target endpoint protections. Modern cloud metadata services that require tokens or special headers are not directly accessible through the affected behavior. This issue is fixed in @backstage/plugin-techdocs-node versions 1.14.7 and 1.15.5.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
