CyberRota Analysis
AI-GeneratedThe @backstage/plugin-techdocs-node package in Backstage versions prior to 1.14.6 is vulnerable to improper validation of mkdocs theme configuration, allowing users with write access to a repository to execute arbitrary code during local or containerized documentation builds. This poses a significant risk as it can lead to unauthorized code execution, potentially compromising the integrity of the development environment. Organizations using Backstage for documentation should prioritize upgrading to versions 1.14.6 or 1.15.4 to mitigate this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process. This issue is fixed in versions 1.14.6 and 1.15.4.
Related CVEs
Other vulnerabilities affecting the same vendor(s)