CVE-2026-106509 | Backstage up to 1.14.5/1.15.3 @backstage/plugin-techdocs-node mkdocs.yml code injection
A vulnerability described as critical has been identified in Backstage up to 1.14.5/1.15.3. This affects an unknown function of the file mkdocs.yml of the component @backstage/plugin-techdocs-node. Such manipulation leads to code injection.
This vulnerability is listed as CVE-2026-106509. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More