
Backstage @backstage/plugin-techdocs-node is vulnerable to arbitrary code execution (CVE-2026-25153) via MkDocs hooks. Evaluate exposure. #Backstage #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-25153-backstage-arbitrary-code-execution
Post summary
The post discloses a new vulnerability (CVE-2026-25153) in Backstage's plugin‑techdocs‑node that allows arbitrary code execution via MkDocs hooks, with no mention of PoC, active exploitation, or mitigation.



