{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/backstage/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:plugin-catalog-backend:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-106498"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-catalog-backend (\u003c 3.9.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eBackstage version 3.9.1 and earlier, specifically within the @backstage/plugin-catalog-backend package, contains a vulnerability identified as CVE-2026-106498. The flaw arises from insufficient validation of URLs used during the resolution of catalog entity placeholders. An authenticated user with the ability to create or edit catalog entities can manipulate these placeholder directives to point toward internal or external resources that should be inaccessible to them.\u003c/p\u003e\n\u003cp\u003eIf the Backstage instance is configured with integration credentials, such as broad GitHub tokens, these credentials may be implicitly used to fetch data from resources outside the intended source repository. This behavior increases the risk of unauthorized data disclosure, as the application fails to enforce appropriate path or domain boundaries during the placeholder resolution process. Defenders should prioritize updating the plugin to version 3.9.1 and reviewing the scope of all configured integration credentials to follow the principle of least privilege.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects users of the Backstage catalog who have permissions to manage entity definitions. Successful exploitation can lead to unauthorized access to sensitive internal data or repository content that the attacker would not otherwise be permitted to view, depending on the scope of the integration tokens assigned to the Backstage service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@backstage/plugin-catalog-backend\u003c/code\u003e package to version 3.9.1 or later to remediate CVE-2026-106498.\u003c/li\u003e\n\u003cli\u003eReview and restrict the scope of integration credentials (such as GitHub, GitLab, or Bitbucket tokens) assigned to the Backstage backend to limit access to only required repositories.\u003c/li\u003e\n\u003cli\u003eAudit existing catalog entity definitions for suspicious placeholder directives that reference unauthorized internal or external endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:55:40Z","date_published":"2026-10-07T22:55:40Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/","summary":"An authenticated user can exploit improper URL validation in Backstage plugin-catalog-backend to access unauthorized resources outside the intended source repository via crafted catalog entity placeholder directives.","title":"Improper URL Validation in Backstage Catalog Entity Placeholder Resolution","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:backend-defaults:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-106492"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["backend-defaults (\u003c 0.17.8)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eBackstage, an open platform for building developer portals, contains a security vulnerability in the \u003ccode\u003e@backstage/backend-defaults\u003c/code\u003e package (versions prior to 0.17.8). The issue arises from the improper preservation of access restrictions during service credential delegation. When an external service credential is configured with limited access, such as read-only permissions, the Backstage backend may fail to enforce these constraints when requests are routed through specific plugin delegation paths.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an attacker or a compromised service to perform actions beyond its intended scope, including executing write operations on plugins that were explicitly restricted to read-only access. Because this bypass occurs within the internal delegation logic, the risk is higher in environments where service-to-service authentication relies heavily on delegated credentials. Defenders must prioritize upgrading the vulnerable package or implementing network-level access controls to restrict access to the backend API.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to the integrity of systems integrated with Backstage. If exploited, an attacker could gain unauthorized write access to resources managed by plugins, potentially modifying sensitive configurations or data. This bypass affects organizations using Backstage for service-to-service interactions where granular access control is enforced via credential delegation. The scope of impact is contingent upon the number of plugins relying on these specific delegation paths and the privilege level of the credentials involved.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@backstage/backend-defaults\u003c/code\u003e package to version 0.17.8 or later immediately to address CVE-2026-106492.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, rotate restricted credentials and replace them with purpose-specific, unrestricted credentials scoped strictly to trusted consumers.\u003c/li\u003e\n\u003cli\u003eRestrict network-level access to all Backstage backend API endpoints, ensuring only authorized callers and internal services can communicate with the API.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:55:32Z","date_published":"2026-10-07T22:55:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-credential-delegation/","summary":"A vulnerability in Backstage's backend-defaults package allows restricted service credentials to bypass defined access restrictions when routing requests through plugin delegation paths, potentially leading to unauthorized privilege escalation.","title":"Improper Access Restriction Enforcement in Backstage Service Delegation","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-credential-delegation/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:plugin-auth-backend-module-oidc-provider:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-106488"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-auth-backend-module-oidc-provider (\u003c 0.4.20)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve-2026-106488","backstage"],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eBackstage's \u003ccode\u003e@backstage/plugin-auth-backend-module-oidc-provider\u003c/code\u003e is affected by an improper authentication vulnerability, tracked as CVE-2026-106488. The flaw exists in the email-based identity resolution process when configured with OIDC providers that do not enforce email verification. An attacker who is authenticated via a malicious or misconfigured OIDC provider can supply an unverified email address that matches an existing user in the Backstage catalog. The application incorrectly maps the attacker's session to the identity of the victim user, allowing for full impersonation of that user's identity and associated permissions within the Backstage environment. This vulnerability affects versions prior to 0.4.20. Defenders should note that this vulnerability does not represent a code injection or direct system compromise, but rather a logic flaw in how identity claims are validated during the OIDC handshake.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized access to catalog entities and sensitive resources managed by Backstage by assuming the identity of another user. This can lead to privilege escalation if the spoofed user account holds administrative roles or high-level access to internal developer portal documentation, service metadata, or infrastructure configurations. No specific victim counts have been reported, but organizations utilizing email-based OIDC identity resolution are at risk if their provider allows unverified addresses.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@backstage/plugin-auth-backend-module-oidc-provider\u003c/code\u003e package to version 0.4.20 or later to include the patch for CVE-2026-106488.\u003c/li\u003e\n\u003cli\u003eReview OIDC provider configurations and disable email-based identity resolution if email verification cannot be strictly enforced at the provider level.\u003c/li\u003e\n\u003cli\u003eMonitor authentication logs for unexpected account mappings or user sessions originating from non-standard or untrusted OIDC provider issuers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:55:19Z","date_published":"2026-10-07T22:55:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-oidc-auth/","summary":"A vulnerability in the Backstage OIDC authentication module allows authenticated users to spoof identities when using email-based resolution with unverified email providers, leading to unauthorized access.","title":"Improper Authentication Vulnerability in Backstage OIDC Provider","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-oidc-auth/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-106486"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-scaffolder-backend-module-bitbucket-cloud (\u003c 0.3.10)","plugin-scaffolder-backend-module-bitbucket-server (\u003c 0.2.25)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","backstage","vulnerability","cve-2026-106486"],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eThe Backstage Scaffolder backend modules for Bitbucket Cloud and Bitbucket Server contain an improper filesystem validation vulnerability, tracked as CVE-2026-106486. This flaw exists within the scaffolder actions responsible for interacting with Bitbucket repositories. An authenticated user who has the privileges to execute templates and the ability to influence the targeted Bitbucket repository parameter can supply malicious input to traverse the filesystem on the backend host. By manipulating these inputs, an attacker may escape the expected working directory, potentially reading sensitive configuration files, modifying application code, or deleting arbitrary files. This vulnerability poses a significant risk to backend integrity and confidentiality, particularly in environments where untrusted users have template creation or execution access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to perform unauthorized file operations on the host running the Backstage backend. This can result in the compromise of backend confidentiality (sensitive file exfiltration), integrity (malicious code injection), or availability (system file deletion). The scope of impact is limited by the permissions of the process running the Backstage backend service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@backstage/plugin-scaffolder-backend-module-bitbucket-cloud\u003c/code\u003e to version 0.3.10 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@backstage/plugin-scaffolder-backend-module-bitbucket-server\u003c/code\u003e to version 0.2.25 or later.\u003c/li\u003e\n\u003cli\u003eApply administrative restrictions on Scaffolder template execution, limiting them to trusted users only.\u003c/li\u003e\n\u003cli\u003eAudit existing Scaffolder templates to identify and restrict actions that accept user-controlled target repository inputs until patching is complete.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:54:58Z","date_published":"2026-10-07T22:54:58Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/","summary":"Authenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.","title":"Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:backstage_plugin_scaffolder_backend_module_sentry:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-106459"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@backstage/plugin-scaffolder-backend-module-sentry (\u003e= 0.3.0, \u003c 0.3.8)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eThe \u003ccode\u003e@backstage/plugin-scaffolder-backend-module-sentry\u003c/code\u003e package (versions 0.3.0 through 0.3.7) contains an improper input validation vulnerability, tracked as CVE-2026-106459. This vulnerability allows an authenticated user with permission to execute scaffolder actions to manipulate the \u003ccode\u003eapiBaseUrl\u003c/code\u003e parameter. By supplying a malicious URL, an attacker can force the Backstage backend server to perform unauthorized outbound HTTP requests. This Server-Side Request Forgery (SSRF) primitive enables the attacker to interact with internal infrastructure or reach unintended external destinations. Crucially, the exploitation of this flaw can result in the disclosure of Sentry integration credentials configured within the Backstage environment. Defenders should upgrade to version 0.3.8 or later and migrate custom \u003ccode\u003eapiBaseUrl\u003c/code\u003e configurations to the global \u003ccode\u003escaffolder.sentry.apiBaseUrl\u003c/code\u003e setting.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated internal user to abuse the Sentry scaffolder action to conduct SSRF attacks. This leads to the potential exfiltration of sensitive integration credentials and provides a foothold to pivot into internal network segments reachable by the Backstage backend service. The severity is high as it facilitates unauthorized credential access and lateral movement potential within the internal development environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@backstage/plugin-scaffolder-backend-module-sentry\u003c/code\u003e package to version 0.3.8 or later.\u003c/li\u003e\n\u003cli\u003eApply the configuration change by moving any custom \u003ccode\u003eapiBaseUrl\u003c/code\u003e values from action-level definitions to the \u003ccode\u003escaffolder.sentry.apiBaseUrl\u003c/code\u003e global setting.\u003c/li\u003e\n\u003cli\u003eRestrict the \u003ccode\u003escaffolder.action.execute\u003c/code\u003e permission for Sentry-related actions to a strictly controlled list of trusted users and templates until patching is complete.\u003c/li\u003e\n\u003cli\u003eDisable the vulnerable Sentry scaffolder actions as a temporary workaround if immediate patching is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:51:00Z","date_published":"2026-10-07T22:51:00Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/","summary":"An authenticated internal user can exploit improper input validation in the Backstage Sentry scaffolder module to trigger SSRF and disclose sensitive integration credentials.","title":"Improper Input Validation in Backstage Sentry Scaffolder Module","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:plugin-scaffolder-backend:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-106501"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-scaffolder-backend (\u003c 3.3.1, \u003e= 3.4.0 \u003c 3.4.1, \u003e= 4.0.0 \u003c 4.0.3, \u003e= 4.0.4 \u003c 4.1.0)","plugin-scaffolder-backend (versions \u003c 3.3.1, 3.4.0-3.4.1, 4.0.0-4.0.3, 4.0.4-4.1.0)","plugin-scaffolder-backend (\u003c 4.1.0)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","cloud-native","backstage","cve","rce","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eThe Backstage Scaffolder plugin (specifically @backstage/plugin-scaffolder-backend) contains a vulnerability identified as CVE-2026-106501, which allows for unauthorized access to sensitive internal execution data. An authenticated user within the Backstage environment can perform read operations on Scaffolder tasks created by other users. If these tasks contain sensitive execution metadata, such as hardcoded credentials or API keys used for external service integration, this information is disclosed. The exposure of these credentials can lead to unauthorized access, modifications, or data exfiltration within the downstream external services integrated into the Backstage workflow. This vulnerability affects multiple versions of the plugin prior to 4.1.0, requiring either an immediate upgrade or the implementation of specific task-read access controls to mitigate unauthorized access to sensitive workflows.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a critical risk to organizations relying on Backstage for service orchestration and workflow automation. If successfully exploited, attackers or malicious insiders can obtain privileged credentials that permit unauthorized interaction with integrated third-party systems. This can result in significant data breaches or unauthorized system state changes across the organization's cloud and development infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade @backstage/plugin-scaffolder-backend to version 4.1.0 or later immediately to patch CVE-2026-106501.\u003c/li\u003e\n\u003cli\u003eIf an upgrade is not immediately possible, modify the Scaffolder configuration to apply the \u003ccode\u003eisTaskOwner\u003c/code\u003e condition to \u003ccode\u003escaffolder.task.read\u003c/code\u003e, ensuring that users are restricted to viewing only their own tasks.\u003c/li\u003e\n\u003cli\u003eAudit active Scaffolder workflows and their integrated services for any potentially compromised credentials that may have been exposed through unauthorized task access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:56:41Z","date_published":"2026-10-07T22:47:15Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-exposure/","summary":"An authenticated user can access internal task execution data in Backstage, potentially exposing credentials stored within Scaffolder tasks to unauthorized parties.","title":"Sensitive Information Exposure in Backstage Scaffolder Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-exposure/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:backstage:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-106509"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-techdocs-node (\u003c 1.15.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eBackstage, an open platform for building developer portals, is vulnerable to a remote code execution (RCE) flaw in the \u003ccode\u003e@backstage/plugin-techdocs-node\u003c/code\u003e package. Tracked as CVE-2026-106509, the issue stems from improper validation of configuration values within the \u003ccode\u003emkdocs.yml\u003c/code\u003e file used by the TechDocs plugin.\u003c/p\u003e\n\u003cp\u003eWhen TechDocs is configured to perform documentation builds locally or within a container environment, an attacker with repository write access can inject malicious configuration directives. These directives are processed during the documentation build stage, leading to the execution of arbitrary commands on the build infrastructure. This vulnerability poses a high risk to organizations that permit documentation builds from untrusted or compromised repository contributors. The vulnerability was remediated in \u003ccode\u003e@backstage/plugin-techdocs-node\u003c/code\u003e version 1.15.4.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains write access to a repository registered in the Backstage catalog.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the \u003ccode\u003emkdocs.yml\u003c/code\u003e file within the repository to include malicious configuration parameters.\u003c/li\u003e\n\u003cli\u003eThe TechDocs plugin triggers a build process for the documentation, either locally or within a container runner.\u003c/li\u003e\n\u003cli\u003eThe build process, facilitated by \u003ccode\u003eplugin-techdocs-node\u003c/code\u003e, parses the manipulated \u003ccode\u003emkdocs.yml\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to properly sanitize or validate the user-controlled configuration values.\u003c/li\u003e\n\u003cli\u003eThe underlying build engine executes the injected commands as part of the MkDocs build process.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution within the build environment (e.g., the Backstage host or the container instance).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary code on the infrastructure hosting the TechDocs build service. This can lead to credential theft, lateral movement within the build environment, or exposure of sensitive data processed by the documentation pipeline. Organizations using TechDocs in 'local' build mode are at the highest risk, though containerized deployments may also be compromised depending on the container runtime's isolation capabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of \u003ccode\u003e@backstage/plugin-techdocs-node\u003c/code\u003e to version 1.15.4 or later across all Backstage instances to address CVE-2026-106509. As a compensatory control for environments where immediate patching is not possible, modify the \u003ccode\u003etechdocs.generator.runIn\u003c/code\u003e configuration to use 'docker' instead of 'local' to enforce container-level isolation. Furthermore, strictly enforce repository write permissions to ensure only trusted users can modify documentation configurations and trigger builds.\u003c/p\u003e\n","date_modified":"2026-10-07T22:56:49Z","date_published":"2026-10-07T16:58:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/","summary":"An improper input validation vulnerability (CVE-2026-106509) in Backstage plugin-techdocs-node allows authenticated users to achieve arbitrary code execution via crafted mkdocs.yml files.","title":"Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Backstage","version":"https://jsonfeed.org/version/1.1"}