SCA: security update for @backstage/plugin-techdocs-backend (GHSA-rg9r-hr7g-5gc2)

medium Tenable Self-Hosted Container Security Plugin ID 473676

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-
techdocs-backend package is affected by improper authorization enforcement for techdocs static content. An
authenticated user with access to one TechDocs documentation site could craft a URL able to read
documentation belonging to a different entity. This only affects deployments using the external TechDocs
builder with an external storage provider (S3, GCS, etc.) and the permission framework enabled. Instances
that do not use the permission framework are unaffected, since TechDocs content is visible to all
authenticated users by design. This issue is fixed in version 2.2.4. (CVE-2026-106489)

Solution

Update the @backstage/plugin-techdocs-backend library and its related packages to version 2.2.4 or later.

See Also

https://github.com/advisories/GHSA-rg9r-hr7g-5gc2

Plugin Details

Severity: Medium

ID: 473676

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/7/2026

Updated: 10/7/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-106489

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-106489