Backstage 是一个用于构建开发者门户的开源框架。在版本 3.5.1、3.6.2、3.7.2、3.8.2 和 3.9.1 之前,@backstage/plugin-catalog-backend 包在目录实体占位符解析过程中存在不正确的 URL 验证问题。经过身份验证的 Backstage 用户可以构造一个包含占位符指令的目录实体,这些指令引用该实体源代码仓库之外的资源。在某些配置下,这可能导致用户访问到本不应向其公开的数据。该问题已在版本 3.5.1、3.6.2、3.7.2、3.8.2 和 3.9.1 中得
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | < 1.49.6 | - |
|
| @backstage | plugin-catalog-backend | < 3.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106501 | 9.6 CRITICAL | Backstage: Sensitive information exposure in Scaffolder |
| CVE-2026-106500 | 8.5 HIGH | Backstage: Improper task state validation in Scaffolder backend |
| CVE-2026-106459 | 8.5 HIGH | Backstage: Improper input validation in Sentry scaffolder actions |
| CVE-2026-106486 | 8.5 HIGH | Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions |
| CVE-2026-106503 | 8.1 HIGH | Backstage: Scaffolder action input authorization bypass |
| CVE-2026-106488 | 8.1 HIGH | Backstage: Improper authentication in the OIDC provider |
| CVE-2026-106455 | 7.7 HIGH | Backstage: Improper validation of MkDocs plugin configuration in TechDocs |
| CVE-2026-106509 | 7.7 HIGH | Backstage: Improper validation of MkDocs theme configuration in TechDocs |
| CVE-2026-106505 | 7.7 HIGH | Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend |
| CVE-2026-106492 | 7.6 HIGH | Backstage: Improper preservation of access restrictions during service credential delegati |
| CVE-2026-106460 | 6.8 MEDIUM | Backstage: Explicit negative email verification can be ignored during shared OAuth profile |
| CVE-2026-106457 | 6.8 MEDIUM | Backstage: Insufficient audience validation in the Cloudflare Access auth provider |
| CVE-2026-106490 | 6.5 MEDIUM | Backstage: Improper input validation in TechDocs static content requests |
| CVE-2026-106489 | 6.5 MEDIUM | Backstage: Improper authorization enforcement for TechDocs static content |
| CVE-2026-106458 | 6.5 MEDIUM | Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates |
| CVE-2026-106504 | 6.5 MEDIUM | Backstage: Sensitive information exposure in scaffolder task logs |
| CVE-2026-106491 | 6.4 MEDIUM | Backstage: Improper input validation in proxy-backend |
| CVE-2026-106462 | 6.4 MEDIUM | Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallb |
| CVE-2026-106463 | 5.4 MEDIUM | Backstage: Improper authorization in GitLab organizational user ingestion |
| CVE-2026-106506 | 5.3 MEDIUM | Backstage: Improper input validation in scaffolder task list ordering |
Showing top 20 of 32 CVEs. View all on vendor page → →
No comments yet