VDB
Sign up
MEDIUM6.5

GHSA-pgf8-28gg-vpr6

Path traversal

Quick fix

GHSA-pgf8-28gg-vpr6 — @backstage/techdocs-common: upgrade to the fixed version with the command below.

npm install @backstage/techdocs-common@0.6.3

Details

### Impact

A malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by setting a particular path for `docs_dir` in `mkdocs.yml`. These files would then be available over the TechDocs backend API.

This vulnerability is mitigated by the fact that an attacker would need access to modify the `mkdocs.yml` in the documentation source code, and would also need access to the TechDocs backend API.

### Patches

The vulnerability is patched in the `0.6.3` release of `@backstage/techdocs-common`.

### For more information

If you have any questions or comments about this advisory:

* Open an issue in the [Backstage repository](https://github.com/backstage/backstage) * Visit our chat, linked to in [Backstage README](https://github.com/backstage/backstage)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@backstage/techdocs-common
Introduced in: 0Fixed in: 0.6.3
Fixnpm install @backstage/techdocs-common@0.6.3

References