Backstage 是一个用于构建开发者门户的开放框架。在 0.3.25 版本之前, 包存在缺陷:该包中的 Confluence 到 Markdown 模板生成模块对输入数据的验证处理不当。由于该模块缺乏充分的输入验证,攻击者可能在模板执行期间影响文件写入操作。成功利用此漏洞需要一名 Backstage 用户运行一个会处理攻击者构造的 Confluence 内容的模板。该问题已在 0.3.25 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | < 1.54.6 | - |
|
| @backstage | plugin-scaffolder-backend-module-confluence-to-markdown | < 0.3.25 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106558 | 8.8 HIGH | Backstage: Improper validation of TechDocs MkDocs configuration |
| CVE-2026-106510 | 7.7 HIGH | Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml |
| CVE-2026-106556 | 7.7 HIGH | Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization |
| CVE-2026-106560 | 7.1 HIGH | Backstage: Improper repository path validation in a Scaffolder backend module |
| CVE-2026-106563 | 5.3 MEDIUM | Backstage: Improper entity validation in deprecated Kubernetes services endpoint |
| CVE-2026-106561 | 5.0 MEDIUM | Backstage: Sensitive information disclosure in Kubernetes resource queries |
| CVE-2026-106562 | 4.3 MEDIUM | Backstage: Incorrect authorization in search engine permission filtering |
No comments yet