PT-2026-5494 · Netflix+1 · Backstage+2
Benjdlambert
·
Published
2026-01-30
·
Updated
2026-02-19
·
CVE-2026-25152
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Backstage versions prior to 1.13.11 and 1.14.1
Description
Backstage is a framework for building developer portals, and
@backstage/plugin-techdocs-node provides functionalities for TechDocs. A path traversal issue exists in the TechDocs local generator when Backstage is configured with techdocs.generator.runIn: local. Symlinks within the documentation directory are followed during the build process, potentially allowing attackers to read arbitrary files from the host filesystem when processing documentation from untrusted sources. File contents are embedded into generated HTML and exposed to users viewing the documentation. The issue occurs because MkDocs follows symlinks during the build process.Recommendations
Versions prior to 1.13.11 should be updated to version 1.13.11 or later.
Versions prior to 1.14.1 should be updated to version 1.14.1 or later.
Switch to
runIn: docker in app-config.yaml.
Restrict write access to TechDocs source repositories to trusted users only.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Backstage/Plugin-Techdocs-Node
Backstage
Mkdocs