{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/plugin-catalog-backend--3.9.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:plugin-catalog-backend:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-106498"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-catalog-backend (\u003c 3.9.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eBackstage version 3.9.1 and earlier, specifically within the @backstage/plugin-catalog-backend package, contains a vulnerability identified as CVE-2026-106498. The flaw arises from insufficient validation of URLs used during the resolution of catalog entity placeholders. An authenticated user with the ability to create or edit catalog entities can manipulate these placeholder directives to point toward internal or external resources that should be inaccessible to them.\u003c/p\u003e\n\u003cp\u003eIf the Backstage instance is configured with integration credentials, such as broad GitHub tokens, these credentials may be implicitly used to fetch data from resources outside the intended source repository. This behavior increases the risk of unauthorized data disclosure, as the application fails to enforce appropriate path or domain boundaries during the placeholder resolution process. Defenders should prioritize updating the plugin to version 3.9.1 and reviewing the scope of all configured integration credentials to follow the principle of least privilege.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects users of the Backstage catalog who have permissions to manage entity definitions. Successful exploitation can lead to unauthorized access to sensitive internal data or repository content that the attacker would not otherwise be permitted to view, depending on the scope of the integration tokens assigned to the Backstage service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@backstage/plugin-catalog-backend\u003c/code\u003e package to version 3.9.1 or later to remediate CVE-2026-106498.\u003c/li\u003e\n\u003cli\u003eReview and restrict the scope of integration credentials (such as GitHub, GitLab, or Bitbucket tokens) assigned to the Backstage backend to limit access to only required repositories.\u003c/li\u003e\n\u003cli\u003eAudit existing catalog entity definitions for suspicious placeholder directives that reference unauthorized internal or external endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:55:40Z","date_published":"2026-10-07T22:55:40Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/","summary":"An authenticated user can exploit improper URL validation in Backstage plugin-catalog-backend to access unauthorized resources outside the intended source repository via crafted catalog entity placeholder directives.","title":"Improper URL Validation in Backstage Catalog Entity Placeholder Resolution","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/"}],"language":"en","title":"CraftedSignal Threat Feed - Plugin-Catalog-Backend (\u003c 3.9.1)","version":"https://jsonfeed.org/version/1.1"}