CVE-2026-29186

critical

Description

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process. A gap in this allowlist allows attackers to craft an mkdocs.yml that causes arbitrary Python code execution, completely bypassing TechDocs' security controls. This issue has been patched in version 1.14.3.

References

https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29186.json

https://github.com/backstage/backstage/security/advisories/GHSA-928r-fm4v-mvrw

https://bugzilla.redhat.com/show_bug.cgi?id=2445480

https://access.redhat.com/security/cve/CVE-2026-29186

https://access.redhat.com/errata/RHSA-2026:9742

https://access.redhat.com/errata/RHSA-2026:13826

Details

Source: Mitre, NVD

Published: 2026-03-07

Updated: 2026-07-15

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00069