OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-106509

HIGH · CVSS 7.7 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The @backstage/plugin-techdocs-node package in Backstage versions prior to 1.14.6 is vulnerable to improper validation of mkdocs theme configuration, allowing users with write access to a repository to execute arbitrary code during local or containerized documentation builds. This poses a significant risk as it can lead to unauthorized code execution, potentially compromising the integrity of the development environment. Organizations using Backstage for documentation should prioritize upgrading to versions 1.14.6 or 1.15.4 to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-106509
Severity
HIGH
CVSS
7.7
EPSS
0.37%

Original NVD Description

Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process. This issue is fixed in versions 1.14.6 and 1.15.4.

Related CVEs

Other vulnerabilities affecting the same vendor(s)