plugin-techdocs-node vulnerabilities
CVEs whose affected-version data names the plugin-techdocs-node package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2026-106557High· 7.7Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can…
CVE-2026-106558High· 8.8Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacke…
CVE-2026-106556High· 7.7Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configuration bypass in techdocs mkdocs.yml sanitization. Insufficient validation of MkDocs config…
CVE-2026-106509High· 7.7Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to buil…
CVE-2026-106508Medium· 5.3Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher …
CVE-2026-106507Medium· 5.3Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree h…
CVE-2026-106455High· 7.7⚖ disputedBackstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin configuration in techdocs. An authentica…