CVE-2026-25153Disclosure(linuxfoundation / backstage)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when TechDocs is configured with `runIn: local`, a malicious actor who can submit or modify a repository's `mkdocs.yml` file can execute arbitrary Python code on the TechDocs build server via MkDocs hooks configuration. @backstage/plugin-techdocs-node versions 1.13.11 and 1.14.1 contain a fix. The fix introduces an allowlist of supported MkDocs configuration keys. Unsupported configuration keys (including `hooks`) are now removed from `mkdocs.yml` before running the generator, with a warning logged to indicate which keys were removed. Users of `@techdocs/cli` should also upgrade to the latest version, which includes the fixed `@backstage/plugin-techdocs-node` dependency. Some workarounds are available. Configure TechDocs with `runIn: docker` instead of `runIn: local` to provide container isolation, though it does not fully mitigate the risk. Limit who can modify `mkdocs.yml` files in repositories that TechDocs processes; only allow trusted contributors. Implement PR review requirements for changes to `mkdocs.yml` files to detect malicious `hooks` configurations before they are merged. Use MkDocs < 1.4.0 (e.g., 1.3.1) which does not support hooks. Note: This may limit access to newer MkDocs features. Building documentation in CI/CD pipelines using `@techdocs/cli` does not mitigate this vulnerability, as the CLI uses the same vulnerable `@backstage/plugin-techdocs-node` package.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • backstage

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-30); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
backstage

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-01-30: 2Mentions · 2026-02-01: 2Technical Details · 2026-01-30: 1Technical Details · 2026-02-01: 101-3002-01
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Backstage @backstage/plugin-techdocs-node is vulnerable to arbitrary code execution (CVE-2026-25153) via MkDocs hooks. Evaluate exposure. #Backstage #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-25153-backstage-arbitrary-code-execution

    Post summary

    The post discloses a new vulnerability (CVE-2026-25153) in Backstage's plugin‑techdocs‑node that allows arbitrary code execution via MkDocs hooks, with no mention of PoC, active exploitation, or mitigation.

    0000079
    1 followersView on X
  • S.Komichevsen Matsuk@w4yh
    General

    BackstageのCVE-2026-25153の説明がkernelの脆弱性並みに長くてdidnt read // NVD - CVE-2026-25153 https://nvd.nist.gov/vuln/detail/CVE-2026-25153

    Post summary

    The tweet comments only on the length of the CVE description, providing no additional technical, exploit, or patch information.

    00000133
    326 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25153 Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25153

    Post summary

    The entry announces a remote code execution flaw in Backstage TechDocs caused by malicious MkDocs configuration, without providing PoC, exploit code, patch information, or evidence of active exploitation.

    0000051
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25153 Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions o… https://www.cve.org/CVERecord?id=CVE-2026-25153

    Post summary

    The entry merely references CVE‑2026‑25153 and the affected Backstage plugin without providing any additional details.

    00000219
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationbackstage---

Explore more