Loading HuntDB...

GHSA-pgf8-28gg-vpr6

GitHub Security Advisory

Path traversal

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact

A malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by setting a particular path for `docs_dir` in `mkdocs.yml`. These files would then be available over the TechDocs backend API.

This vulnerability is mitigated by the fact that an attacker would need access to modify the `mkdocs.yml` in the documentation source code, and would also need access to the TechDocs backend API.

### Patches

The vulnerability is patched in the `0.6.3` release of `@backstage/techdocs-common`.

### For more information

If you have any questions or comments about this advisory:

* Open an issue in the [Backstage repository](https://github.com/backstage/backstage)
* Visit our chat, linked to in [Backstage README](https://github.com/backstage/backstage)

Affected Packages

npm @backstage/techdocs-common
Affected versions: 0 (fixed in 0.6.3)

Related CVEs

Key Information

GHSA ID
GHSA-pgf8-28gg-vpr6
Published
June 4, 2021 7:09 PM
Last Modified
June 7, 2021 6:55 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
@backstage/techdocs-common
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.