CVE-2026-25152
CVE-2026-25152 is a medium-severity vulnerability in Linuxfoundation Backstage with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 0% (32nd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-5002
- Weakness: CWE-22
- Affected product: Linuxfoundation Backstage
- Published:
- Last modified:
Description
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vulnerability in the TechDocs local generator allows attackers to read arbitrary files from the host filesystem when Backstage is configured with `techdocs.generator.runIn: local`. When processing documentation from untrusted sources, symlinks within the docs directory are followed by MkDocs during the build process. File contents are embedded into generated HTML and exposed to users who can view the documentation. This vulnerability is fixed in` @backstage/plugin-techdocs-node` versions 1.13.11 and 1.14.1. Some workarounds are available. Switch to `runIn: docker` in `app-config.yaml` and/or restrict write access to TechDocs source repositories to trusted users only.
Frequently asked questions
- What is CVE-2026-25152?
- Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vulnerability in the TechDocs local generator allows attackers to read arbitrary files from the host filesystem when Backstage is configured with `techdocs.generator.runIn: local`. When processing documentation from untrusted sources, symlinks within the docs directory are followed by MkDocs during the build process. File contents are embedded into generated HTML and exposed to users who can view the documentation. This vulnerability is fixed in` @backstage/plugin-techdocs-node` versions 1.13.11 and 1.14.1. Some workarounds are available. Switch to `runIn: docker` in `app-config.yaml` and/or restrict write access to TechDocs source repositories to trusted users only.
- How severe is CVE-2026-25152?
- CVE-2026-25152 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-25152 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (32nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-25152?
- CVE-2026-25152 affects Linuxfoundation Backstage. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-25152?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-25152 have an EU (EUVD) identifier?
- Yes. CVE-2026-25152 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-5002.
- When was CVE-2026-25152 published?
- CVE-2026-25152 was published on 2026-01-30 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:*
More vulnerabilities in Linuxfoundation Backstage
- CVE-2021-43783 — High (CVSS 8.5): @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions…
- CVE-2023-35926 — High (CVSS 8.0): Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating…
- CVE-2026-25153 — High (CVSS 7.7): Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common…
- CVE-2026-32236 — High (CVSS 7.5): Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF)…
- CVE-2021-41151 — Medium (CVSS 6.8): Backstage is an open platform for building developer portals. In affected versions A malicious actor could read…
- CVE-2024-46976 — Medium (CVSS 6.5): Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs…
All CVEs affecting Linuxfoundation Backstage →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.