Vulnerability record · CVE-2021-32662 · published 3 June 2021
CVE-2021-32662: Linuxfoundation backstage path traversal vulnerability
Linuxfoundation · Backstage
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by setting a particular path for `docs_dir` in `mkdocs.yml`. These files would then be available over the TechDocs backend API. This vulnerability is mitigated by the fact that an attacker would need access to modify the `mkdocs.yml` in the documentation source code, and would also need access to the TechDocs backend API. The vulnerability is patched in the `0.6.3` release of `@backstage/techdocs-common`.
Description
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by setting a particular path for `docs_dir` in `mkdocs.yml`. These files would then be available over the TechDocs backend API. This vulnerability is mitigated by the fact that an attacker would need access to modify the `mkdocs.yml` in the documentation source code, and would also need access to the TechDocs backend API. The vulnerability is patched in the `0.6.3` release of `@backstage/techdocs-common`.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/backstage/backstage/commit/8cefadca04cbf01d0394b0cb1983247e5f1d6208 | PatchThird Party Advisory |
| https://github.com/backstage/backstage/releases/tag/release-2021-05-27 | Release NotesThird Party Advisory |
| https://github.com/backstage/backstage/security/advisories/GHSA-pgf8-28gg-vpr6 | Third Party Advisory |
| https://github.com/backstage/backstage/commit/8cefadca04cbf01d0394b0cb1983247e5f1d6208 | PatchThird Party Advisory |
| https://github.com/backstage/backstage/releases/tag/release-2021-05-27 | Release NotesThird Party Advisory |
| https://github.com/backstage/backstage/security/advisories/GHSA-pgf8-28gg-vpr6 | Third Party Advisory |
Track CVE-2021-32662 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32662), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.