GHSA-928r-fm4v-mvrw
HIGHCVE-2026-29186This is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process.
- Affected
- <= 1.14.2
- Fixed in
- 1.14.3
- Weakness
- CWE-74
- Published
- 2026-03-05
- Source
- github