Skip to content
Threat Feed

Vendor

Backstage

7 briefs RSS
high advisory

Improper URL Validation in Backstage Catalog Entity Placeholder Resolution

An authenticated user can exploit improper URL validation in Backstage plugin-catalog-backend to access unauthorized resources outside the intended source repository via crafted catalog entity placeholder directives.

plugin-catalog-backend
1c
high advisory

Improper Access Restriction Enforcement in Backstage Service Delegation

A vulnerability in Backstage's backend-defaults package allows restricted service credentials to bypass defined access restrictions when routing requests through plugin delegation paths, potentially leading to unauthorized privilege escalation.

backend-defaults
1t 1c
high advisory

Improper Authentication Vulnerability in Backstage OIDC Provider

A vulnerability in the Backstage OIDC authentication module allows authenticated users to spoof identities when using email-based resolution with unverified email providers, leading to unauthorized access.

plugin-auth-backend-module-oidc-provider authentication-bypass cve-2026-106488 backstage
1t 1c
high advisory

Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules

Authenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.

plugin-scaffolder-backend-module-bitbucket-cloud +1 path-traversal backstage vulnerability cve-2026-106486
1t 1c
high advisory

Improper Input Validation in Backstage Sentry Scaffolder Module

An authenticated internal user can exploit improper input validation in the Backstage Sentry scaffolder module to trigger SSRF and disclose sensitive integration credentials.

@backstage/plugin-scaffolder-backend-module-sentry web-vulnerability ssrf supply-chain
2t 1c
critical advisory

Sensitive Information Exposure in Backstage Scaffolder Plugin

An authenticated user can access internal task execution data in Backstage, potentially exposing credentials stored within Scaffolder tasks to unauthorized parties.

plugin-scaffolder-backend +2 vulnerability cloud-native backstage cve rce privilege-escalation
2t 1c
high advisory

Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration

An improper input validation vulnerability (CVE-2026-106509) in Backstage plugin-techdocs-node allows authenticated users to achieve arbitrary code execution via crafted mkdocs.yml files.

plugin-techdocs-node vulnerability rce supply-chain
3t 1c