Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29186

Опубликовано: 07 мар. 2026
Источник: redhat
CVSS3: 9.1

Описание

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process. A gap in this allowlist allows attackers to craft an mkdocs.yml that causes arbitrary Python code execution, completely bypassing TechDocs' security controls. This issue has been patched in version 1.14.3.

A flaw was found in Backstage. The backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process. A gap in this allowlist allows attackers to craft an mkdocs.yml file that causes arbitrary Python code execution.

Отчет

To exploit this issue, an attacker needs commit access to a repository that Backstage is configured to track and build in order to introduce a malicious mkdocs.yml file into the TechDocs build pipeline. Additionally, an attacker can execute arbitrary Python code but the payload is confined by the permissions granted to the TechDocs build process which is typically a restricted service account, limiting the impact of this vulnerability. Due to these reasons, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

To mitigate this issue, enable docker isolation by updating the Backstage configuration to use 'runIn: docker' instead of 'runIn: local', confining the arbitrary Python code execution to a containerized environment. Additionally, limit commit access to repositories tracked by Backstage to trusted contributors only, and enforce mandatory pull request (PR) reviews for any modifications made to the mkdocs.yml file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Self-service automation portal 2ansible-automation-platform/automation-portalAffected
Red Hat Developer Hub 1.8rhdh/rhdh-hub-rhel9FixedRHSA-2026:974222.04.2026
Red Hat Developer Hub 1.9rhdh/rhdh-hub-rhel9FixedRHSA-2026:1382605.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-791
https://bugzilla.redhat.com/show_bug.cgi?id=2445480backstage/plugin-techdocs-node: TechDocs Mkdocs configuration key enables arbitrary code execution

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
5 месяцев назад

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process. A gap in this allowlist allows attackers to craft an mkdocs.yml that causes arbitrary Python code execution, completely bypassing TechDocs' security controls. This issue has been patched in version 1.14.3.

CVSS3: 7.7
github
5 месяцев назад

TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution

9.1 Critical

CVSS3