An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built.
Patched in @backstage/plugin-techdocs-node, version 1.15.4.
If you cannot upgrade immediately:
techdocs.builder: external to isolate TechDocs builds in a container.markdown_extensions values in their mkdocs.yml files.{
"cwe_ids": [
"CWE-183",
"CWE-470"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T18:03:22Z",
"nvd_published_at": "2026-10-07T15:17:12Z",
"severity": "HIGH"
}