<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:backstage:plugin-Catalog-Backend:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3abackstageplugin-catalog-backend/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:55:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3abackstageplugin-catalog-backend/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper URL Validation in Backstage Catalog Entity Placeholder Resolution</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/</link><pubDate>Wed, 07 Oct 2026 22:55:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/</guid><description>An authenticated user can exploit improper URL validation in Backstage plugin-catalog-backend to access unauthorized resources outside the intended source repository via crafted catalog entity placeholder directives.</description><content:encoded><![CDATA[<p>Backstage version 3.9.1 and earlier, specifically within the @backstage/plugin-catalog-backend package, contains a vulnerability identified as CVE-2026-106498. The flaw arises from insufficient validation of URLs used during the resolution of catalog entity placeholders. An authenticated user with the ability to create or edit catalog entities can manipulate these placeholder directives to point toward internal or external resources that should be inaccessible to them.</p>
<p>If the Backstage instance is configured with integration credentials, such as broad GitHub tokens, these credentials may be implicitly used to fetch data from resources outside the intended source repository. This behavior increases the risk of unauthorized data disclosure, as the application fails to enforce appropriate path or domain boundaries during the placeholder resolution process. Defenders should prioritize updating the plugin to version 3.9.1 and reviewing the scope of all configured integration credentials to follow the principle of least privilege.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects users of the Backstage catalog who have permissions to manage entity definitions. Successful exploitation can lead to unauthorized access to sensitive internal data or repository content that the attacker would not otherwise be permitted to view, depending on the scope of the integration tokens assigned to the Backstage service.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>@backstage/plugin-catalog-backend</code> package to version 3.9.1 or later to remediate CVE-2026-106498.</li>
<li>Review and restrict the scope of integration credentials (such as GitHub, GitLab, or Bitbucket tokens) assigned to the Backstage backend to limit access to only required repositories.</li>
<li>Audit existing catalog entity definitions for suspicious placeholder directives that reference unauthorized internal or external endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>