Логотип exploitDog
bind:CVE-2026-29186
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-29186

Количество 3

Количество 3

redhat логотип

CVE-2026-29186

20 дней назад

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process. A gap in this allowlist allows attackers to craft an mkdocs.yml that causes arbitrary Python code execution, completely bypassing TechDocs' security controls. This issue has been patched in version 1.14.3.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-29186

20 дней назад

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process. A gap in this allowlist allows attackers to craft an mkdocs.yml that causes arbitrary Python code execution, completely bypassing TechDocs' security controls. This issue has been patched in version 1.14.3.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-928r-fm4v-mvrw

23 дня назад

TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-29186

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process. A gap in this allowlist allows attackers to craft an mkdocs.yml that causes arbitrary Python code execution, completely bypassing TechDocs' security controls. This issue has been patched in version 1.14.3.

CVSS3: 9.1
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-29186

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process. A gap in this allowlist allows attackers to craft an mkdocs.yml that causes arbitrary Python code execution, completely bypassing TechDocs' security controls. This issue has been patched in version 1.14.3.

CVSS3: 7.7
0%
Низкий
20 дней назад
github логотип
GHSA-928r-fm4v-mvrw

TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution

CVSS3: 7.7
0%
Низкий
23 дня назад

Уязвимостей на страницу