<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Backstage - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/backstage/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:55:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/backstage/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper URL Validation in Backstage Catalog Entity Placeholder Resolution</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/</link><pubDate>Wed, 07 Oct 2026 22:55:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-url-validation/</guid><description>An authenticated user can exploit improper URL validation in Backstage plugin-catalog-backend to access unauthorized resources outside the intended source repository via crafted catalog entity placeholder directives.</description><content:encoded><![CDATA[<p>Backstage version 3.9.1 and earlier, specifically within the @backstage/plugin-catalog-backend package, contains a vulnerability identified as CVE-2026-106498. The flaw arises from insufficient validation of URLs used during the resolution of catalog entity placeholders. An authenticated user with the ability to create or edit catalog entities can manipulate these placeholder directives to point toward internal or external resources that should be inaccessible to them.</p>
<p>If the Backstage instance is configured with integration credentials, such as broad GitHub tokens, these credentials may be implicitly used to fetch data from resources outside the intended source repository. This behavior increases the risk of unauthorized data disclosure, as the application fails to enforce appropriate path or domain boundaries during the placeholder resolution process. Defenders should prioritize updating the plugin to version 3.9.1 and reviewing the scope of all configured integration credentials to follow the principle of least privilege.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects users of the Backstage catalog who have permissions to manage entity definitions. Successful exploitation can lead to unauthorized access to sensitive internal data or repository content that the attacker would not otherwise be permitted to view, depending on the scope of the integration tokens assigned to the Backstage service.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>@backstage/plugin-catalog-backend</code> package to version 3.9.1 or later to remediate CVE-2026-106498.</li>
<li>Review and restrict the scope of integration credentials (such as GitHub, GitLab, or Bitbucket tokens) assigned to the Backstage backend to limit access to only required repositories.</li>
<li>Audit existing catalog entity definitions for suspicious placeholder directives that reference unauthorized internal or external endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item><item><title>Improper Access Restriction Enforcement in Backstage Service Delegation</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-credential-delegation/</link><pubDate>Wed, 07 Oct 2026 22:55:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-credential-delegation/</guid><description>A vulnerability in Backstage's backend-defaults package allows restricted service credentials to bypass defined access restrictions when routing requests through plugin delegation paths, potentially leading to unauthorized privilege escalation.</description><content:encoded><![CDATA[<p>Backstage, an open platform for building developer portals, contains a security vulnerability in the <code>@backstage/backend-defaults</code> package (versions prior to 0.17.8). The issue arises from the improper preservation of access restrictions during service credential delegation. When an external service credential is configured with limited access, such as read-only permissions, the Backstage backend may fail to enforce these constraints when requests are routed through specific plugin delegation paths.</p>
<p>This flaw allows an attacker or a compromised service to perform actions beyond its intended scope, including executing write operations on plugins that were explicitly restricted to read-only access. Because this bypass occurs within the internal delegation logic, the risk is higher in environments where service-to-service authentication relies heavily on delegated credentials. Defenders must prioritize upgrading the vulnerable package or implementing network-level access controls to restrict access to the backend API.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to the integrity of systems integrated with Backstage. If exploited, an attacker could gain unauthorized write access to resources managed by plugins, potentially modifying sensitive configurations or data. This bypass affects organizations using Backstage for service-to-service interactions where granular access control is enforced via credential delegation. The scope of impact is contingent upon the number of plugins relying on these specific delegation paths and the privilege level of the credentials involved.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>@backstage/backend-defaults</code> package to version 0.17.8 or later immediately to address CVE-2026-106492.</li>
<li>If an immediate upgrade is not possible, rotate restricted credentials and replace them with purpose-specific, unrestricted credentials scoped strictly to trusted consumers.</li>
<li>Restrict network-level access to all Backstage backend API endpoints, ensuring only authorized callers and internal services can communicate with the API.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item><item><title>Improper Authentication Vulnerability in Backstage OIDC Provider</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-oidc-auth/</link><pubDate>Wed, 07 Oct 2026 22:55:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-oidc-auth/</guid><description>A vulnerability in the Backstage OIDC authentication module allows authenticated users to spoof identities when using email-based resolution with unverified email providers, leading to unauthorized access.</description><content:encoded><![CDATA[<p>Backstage's <code>@backstage/plugin-auth-backend-module-oidc-provider</code> is affected by an improper authentication vulnerability, tracked as CVE-2026-106488. The flaw exists in the email-based identity resolution process when configured with OIDC providers that do not enforce email verification. An attacker who is authenticated via a malicious or misconfigured OIDC provider can supply an unverified email address that matches an existing user in the Backstage catalog. The application incorrectly maps the attacker's session to the identity of the victim user, allowing for full impersonation of that user's identity and associated permissions within the Backstage environment. This vulnerability affects versions prior to 0.4.20. Defenders should note that this vulnerability does not represent a code injection or direct system compromise, but rather a logic flaw in how identity claims are validated during the OIDC handshake.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthorized access to catalog entities and sensitive resources managed by Backstage by assuming the identity of another user. This can lead to privilege escalation if the spoofed user account holds administrative roles or high-level access to internal developer portal documentation, service metadata, or infrastructure configurations. No specific victim counts have been reported, but organizations utilizing email-based OIDC identity resolution are at risk if their provider allows unverified addresses.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>@backstage/plugin-auth-backend-module-oidc-provider</code> package to version 0.4.20 or later to include the patch for CVE-2026-106488.</li>
<li>Review OIDC provider configurations and disable email-based identity resolution if email verification cannot be strictly enforced at the provider level.</li>
<li>Monitor authentication logs for unexpected account mappings or user sessions originating from non-standard or untrusted OIDC provider issuers.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve-2026-106488</category><category>backstage</category></item><item><title>Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/</link><pubDate>Wed, 07 Oct 2026 22:54:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/</guid><description>Authenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.</description><content:encoded><![CDATA[<p>The Backstage Scaffolder backend modules for Bitbucket Cloud and Bitbucket Server contain an improper filesystem validation vulnerability, tracked as CVE-2026-106486. This flaw exists within the scaffolder actions responsible for interacting with Bitbucket repositories. An authenticated user who has the privileges to execute templates and the ability to influence the targeted Bitbucket repository parameter can supply malicious input to traverse the filesystem on the backend host. By manipulating these inputs, an attacker may escape the expected working directory, potentially reading sensitive configuration files, modifying application code, or deleting arbitrary files. This vulnerability poses a significant risk to backend integrity and confidentiality, particularly in environments where untrusted users have template creation or execution access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to perform unauthorized file operations on the host running the Backstage backend. This can result in the compromise of backend confidentiality (sensitive file exfiltration), integrity (malicious code injection), or availability (system file deletion). The scope of impact is limited by the permissions of the process running the Backstage backend service.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade <code>@backstage/plugin-scaffolder-backend-module-bitbucket-cloud</code> to version 0.3.10 or later.</li>
<li>Upgrade <code>@backstage/plugin-scaffolder-backend-module-bitbucket-server</code> to version 0.2.25 or later.</li>
<li>Apply administrative restrictions on Scaffolder template execution, limiting them to trusted users only.</li>
<li>Audit existing Scaffolder templates to identify and restrict actions that accept user-controlled target repository inputs until patching is complete.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>backstage</category><category>vulnerability</category><category>cve-2026-106486</category></item><item><title>Improper Input Validation in Backstage Sentry Scaffolder Module</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/</link><pubDate>Wed, 07 Oct 2026 22:51:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/</guid><description>An authenticated internal user can exploit improper input validation in the Backstage Sentry scaffolder module to trigger SSRF and disclose sensitive integration credentials.</description><content:encoded><![CDATA[<p>The <code>@backstage/plugin-scaffolder-backend-module-sentry</code> package (versions 0.3.0 through 0.3.7) contains an improper input validation vulnerability, tracked as CVE-2026-106459. This vulnerability allows an authenticated user with permission to execute scaffolder actions to manipulate the <code>apiBaseUrl</code> parameter. By supplying a malicious URL, an attacker can force the Backstage backend server to perform unauthorized outbound HTTP requests. This Server-Side Request Forgery (SSRF) primitive enables the attacker to interact with internal infrastructure or reach unintended external destinations. Crucially, the exploitation of this flaw can result in the disclosure of Sentry integration credentials configured within the Backstage environment. Defenders should upgrade to version 0.3.8 or later and migrate custom <code>apiBaseUrl</code> configurations to the global <code>scaffolder.sentry.apiBaseUrl</code> setting.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated internal user to abuse the Sentry scaffolder action to conduct SSRF attacks. This leads to the potential exfiltration of sensitive integration credentials and provides a foothold to pivot into internal network segments reachable by the Backstage backend service. The severity is high as it facilitates unauthorized credential access and lateral movement potential within the internal development environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>@backstage/plugin-scaffolder-backend-module-sentry</code> package to version 0.3.8 or later.</li>
<li>Apply the configuration change by moving any custom <code>apiBaseUrl</code> values from action-level definitions to the <code>scaffolder.sentry.apiBaseUrl</code> global setting.</li>
<li>Restrict the <code>scaffolder.action.execute</code> permission for Sentry-related actions to a strictly controlled list of trusted users and templates until patching is complete.</li>
<li>Disable the vulnerable Sentry scaffolder actions as a temporary workaround if immediate patching is not possible.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>ssrf</category><category>supply-chain</category></item><item><title>Sensitive Information Exposure in Backstage Scaffolder Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-exposure/</link><pubDate>Wed, 07 Oct 2026 22:47:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-exposure/</guid><description>An authenticated user can access internal task execution data in Backstage, potentially exposing credentials stored within Scaffolder tasks to unauthorized parties.</description><content:encoded><![CDATA[<p>The Backstage Scaffolder plugin (specifically @backstage/plugin-scaffolder-backend) contains a vulnerability identified as CVE-2026-106501, which allows for unauthorized access to sensitive internal execution data. An authenticated user within the Backstage environment can perform read operations on Scaffolder tasks created by other users. If these tasks contain sensitive execution metadata, such as hardcoded credentials or API keys used for external service integration, this information is disclosed. The exposure of these credentials can lead to unauthorized access, modifications, or data exfiltration within the downstream external services integrated into the Backstage workflow. This vulnerability affects multiple versions of the plugin prior to 4.1.0, requiring either an immediate upgrade or the implementation of specific task-read access controls to mitigate unauthorized access to sensitive workflows.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a critical risk to organizations relying on Backstage for service orchestration and workflow automation. If successfully exploited, attackers or malicious insiders can obtain privileged credentials that permit unauthorized interaction with integrated third-party systems. This can result in significant data breaches or unauthorized system state changes across the organization's cloud and development infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade @backstage/plugin-scaffolder-backend to version 4.1.0 or later immediately to patch CVE-2026-106501.</li>
<li>If an upgrade is not immediately possible, modify the Scaffolder configuration to apply the <code>isTaskOwner</code> condition to <code>scaffolder.task.read</code>, ensuring that users are restricted to viewing only their own tasks.</li>
<li>Audit active Scaffolder workflows and their integrated services for any potentially compromised credentials that may have been exposed through unauthorized task access.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>cloud-native</category><category>backstage</category><category>cve</category><category>rce</category><category>privilege-escalation</category></item><item><title>Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/</link><pubDate>Wed, 07 Oct 2026 16:58:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-techdocs-rce/</guid><description>An improper input validation vulnerability (CVE-2026-106509) in Backstage plugin-techdocs-node allows authenticated users to achieve arbitrary code execution via crafted mkdocs.yml files.</description><content:encoded><![CDATA[<p>Backstage, an open platform for building developer portals, is vulnerable to a remote code execution (RCE) flaw in the <code>@backstage/plugin-techdocs-node</code> package. Tracked as CVE-2026-106509, the issue stems from improper validation of configuration values within the <code>mkdocs.yml</code> file used by the TechDocs plugin.</p>
<p>When TechDocs is configured to perform documentation builds locally or within a container environment, an attacker with repository write access can inject malicious configuration directives. These directives are processed during the documentation build stage, leading to the execution of arbitrary commands on the build infrastructure. This vulnerability poses a high risk to organizations that permit documentation builds from untrusted or compromised repository contributors. The vulnerability was remediated in <code>@backstage/plugin-techdocs-node</code> version 1.15.4.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker gains write access to a repository registered in the Backstage catalog.</li>
<li>Attacker modifies the <code>mkdocs.yml</code> file within the repository to include malicious configuration parameters.</li>
<li>The TechDocs plugin triggers a build process for the documentation, either locally or within a container runner.</li>
<li>The build process, facilitated by <code>plugin-techdocs-node</code>, parses the manipulated <code>mkdocs.yml</code> file.</li>
<li>The plugin fails to properly sanitize or validate the user-controlled configuration values.</li>
<li>The underlying build engine executes the injected commands as part of the MkDocs build process.</li>
<li>Attacker achieves remote code execution within the build environment (e.g., the Backstage host or the container instance).</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an attacker to execute arbitrary code on the infrastructure hosting the TechDocs build service. This can lead to credential theft, lateral movement within the build environment, or exposure of sensitive data processed by the documentation pipeline. Organizations using TechDocs in 'local' build mode are at the highest risk, though containerized deployments may also be compromised depending on the container runtime's isolation capabilities.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of <code>@backstage/plugin-techdocs-node</code> to version 1.15.4 or later across all Backstage instances to address CVE-2026-106509. As a compensatory control for environments where immediate patching is not possible, modify the <code>techdocs.generator.runIn</code> configuration to use 'docker' instead of 'local' to enforce container-level isolation. Furthermore, strictly enforce repository write permissions to ensure only trusted users can modify documentation configurations and trigger builds.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>supply-chain</category></item></channel></rss>