CVE-2026-106505
Last modified
CVE-2026-106505 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| backstage | backstage | < 1.50.5; >= 1.51.0-next.0, < 1.54.6 |
| @backstage | plugin-techdocs-node | < 1.14.6; >= 1.15.0, < 1.15.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-106505?
How severe is CVE-2026-106505?
How do I fix CVE-2026-106505?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10650A flaw has been found in warmcat libwebsockets up to 4.5.8. …5.5
- CVE-2026-106500Backstage is an open framework for building developer portal…8.5
- CVE-2026-106501Backstage is an open framework for building developer portal…9.6
- CVE-2026-106502Backstage is an open framework for building developer portal…5.3
- CVE-2026-106503Backstage is an open framework for building developer portal…8.1
- CVE-2026-106504Backstage is an open framework for building developer portal…6.5
- CVE-2026-106506Backstage is an open framework for building developer portal…5.3
- CVE-2026-106507Backstage is an open framework for building developer portal…5.3
- CVE-2026-106508Backstage is an open framework for building developer portal…5.3
- CVE-2026-106509Backstage is an open framework for building developer portal…7.7
- CVE-2026-10651bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sd…6.5
- CVE-2026-106510Backstage is an open framework for building developer portal…7.7
Are you affected by CVE-2026-106505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
