Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation.
Patched in@backstage/plugin-techdocs-node version 1.15.4
If you cannot upgrade immediately:
runIn: docker instead of runIn: local. This provides container isolation, though it does not fully mitigate the risk.{
"cwe_ids": [
"CWE-426",
"CWE-436"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T16:23:52Z",
"nvd_published_at": "2026-10-06T22:17:05Z",
"severity": "HIGH"
}