Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml
An authenticated user who can register catalog entities can provide a crafted mkdocs.yml causing arbitrary OS command execution on the TechDocs build host when the docs are built.
github.com /advisories/GHSA-4488-j8vj-vqqv
github.com /backstage/backstage/commit/02cd7cdbb18b687446277b5602adaee7f1d53cbb
github.com /backstage/backstage/commit/a900a9953c8f7ad3ba1906d1d257725a9996cc9d
github.com /backstage/backstage/releases/tag/v1.50.5
github.com /backstage/backstage/releases/tag/v1.54.6
github.com /backstage/backstage/security/advisories/GHSA-4488-j8vj-vqqv
nvd.nist.gov /vuln/detail/CVE-2026-106510
Code Behaviors & Features
Detect and mitigate CVE-2026-106510 with GitLab Dependency Scanning
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
