← Back to CVE List
CVE-2026-106498NVD
Vulnerability Summary
Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1.
CVSS v3.1 Base Metrics — Score 7.7 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone
Affected & Patched Versions
Not provided by NVD for this CVE.
Not provided by NVD for this CVE.
External References
- https://github.com/backstage/backstage/commit/0b0f6fc89b4eb4872c76a498abbe1dc65998bb6e
- https://github.com/backstage/backstage/commit/286bfc1f9cc3608a073b41016be302785be385d1
- https://github.com/backstage/backstage/commit/61a10f19926aeda7f4a32de48d733e6710584634
- https://github.com/backstage/backstage/commit/99729e925fd2bd40ba210022351a0ee6318e6197
- https://github.com/backstage/backstage/commit/e786ac309ed2d775daf2309393c015c43902d6f6
- https://github.com/backstage/backstage/releases/tag/v1.49.6
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.51.3
- https://github.com/backstage/backstage/releases/tag/v1.53.2
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/backstage/backstage/security/advisories/GHSA-qgvj-qcf8-xq73