Skip to content
Threat Feed
high advisory

Improper URL Validation in Backstage Catalog Entity Placeholder Resolution

An authenticated user can exploit improper URL validation in Backstage plugin-catalog-backend to access unauthorized resources outside the intended source repository via crafted catalog entity placeholder directives.

CVE search metadata

CVE search record: CVE-2026-106498. Severity: high. CVSS: 7.7. KEV: no. Product: plugin-catalog-backend (< 3.9.1). Brief: Improper URL Validation in Backstage Catalog Entity Placeholder Resolution. Brief link: https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/

Backstage version 3.9.1 and earlier, specifically within the @backstage/plugin-catalog-backend package, contains a vulnerability identified as CVE-2026-106498. The flaw arises from insufficient validation of URLs used during the resolution of catalog entity placeholders. An authenticated user with the ability to create or edit catalog entities can manipulate these placeholder directives to point toward internal or external resources that should be inaccessible to them.

If the Backstage instance is configured with integration credentials, such as broad GitHub tokens, these credentials may be implicitly used to fetch data from resources outside the intended source repository. This behavior increases the risk of unauthorized data disclosure, as the application fails to enforce appropriate path or domain boundaries during the placeholder resolution process. Defenders should prioritize updating the plugin to version 3.9.1 and reviewing the scope of all configured integration credentials to follow the principle of least privilege.

Impact

The vulnerability affects users of the Backstage catalog who have permissions to manage entity definitions. Successful exploitation can lead to unauthorized access to sensitive internal data or repository content that the attacker would not otherwise be permitted to view, depending on the scope of the integration tokens assigned to the Backstage service.

Recommendation

  • Upgrade the @backstage/plugin-catalog-backend package to version 3.9.1 or later to remediate CVE-2026-106498.
  • Review and restrict the scope of integration credentials (such as GitHub, GitLab, or Bitbucket tokens) assigned to the Backstage backend to limit access to only required repositories.
  • Audit existing catalog entity definitions for suspicious placeholder directives that reference unauthorized internal or external endpoints.

Immediate actions

Upgrade @backstage/plugin-catalog-backend to version 3.9.1

IT Operations 48h

Mitigations

Restrict scope of integration credentials to the minimum necessary repositories

immediate Security Engineering

CVE-2026-106498