CVE-2026-106510 | Backstage up to 1.14.5 plugin-techdocs-node mkdocs.yml os command injection

SecurityVulns

A vulnerability classified as problematic has been found in Backstage up to 1.14.5. The impacted element is an unknown function of the file mkdocs.yml of the component plugin-techdocs-node. This manipulation causes os command injection.

This vulnerability is registered as CVE-2026-106510. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More