CVE-2026-106509
linuxfoundation backstage plugin-techdocs-node
Summary
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process. This issue is fixed in versions 1.14.6 and 1.15.4.
Published 2026-10-06 · first seen here 2026-10-10
Analysis & write-ups
No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.
Where it shows in your logs
Server or web application · Command or code injection (remote code execution) medium confidence
What to look for
- Shell metacharacters or encoded payloads in request parameters (; | ` $( %0a)
- The vulnerable process spawning shells, then downloaders (curl, wget, certutil, Invoke-WebRequest)
- The application's process (w3wp.exe, java, tomcat, node, php-fpm, httpd, python) starting shells or LOLBins (cmd, powershell, sh, bash, curl, wget, certutil)
- New script files in web roots (.jsp, .aspx, .php): a web shell
- Requests to unusual URLs on the application from internet IPs right before any of the above
- Outbound connections from the server to new external IPs
Data sources
Web server and WAF logs · ATT&CK DS0015 Application Log Content
- Sentinel
W3CIISLogAppServiceHTTPLogsAzureDiagnostics (Application Gateway / Front Door WAF)_Im_WebSession- Splunk
Web.Webms:iis:autoaccess_combinedWAF / proxy sourcetypes- CrowdStrike
Falcon Next-Gen SIEM: third-party web / WAF / proxy logs
Process creation · ATT&CK DS0009 Process Creation
- Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate- Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)- CrowdStrike
ProcessRollup2SyntheticProcessRollup2
File creation · ATT&CK DS0022 File Creation
- Sentinel
DeviceFileEventsSysmon Event ID 11_Im_FileEvent- Splunk
Endpoint.FilesystemSysmon Event ID 11- CrowdStrike
NewExecutableWrittenNewScriptWritten*FileWritten events
Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow
- Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession- Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)- CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6
A generic baseline worked out from the product type and weakness (CWE-1336, CWE-94), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.
References
- NVD entry
- https://github.com/backstage/backstage/commit/02cd7cdbb18b687446277b5602adaee7f1d53cbb
- https://github.com/backstage/backstage/commit/a900a9953c8f7ad3ba1906d1d257725a9996cc9d
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/backstage/backstage/security/advisories/GHSA-8w7q-29mw-gf5c