Backstage 是用于构建开发者门户的开源框架。在 0.3.25 版本之前,@backstage/plugin-scaffolder-backend-module-confluence-to-markdown 软件包存在一个问题:在 Scaffolder 后端模块中,对仓库路径的验证不当。经过身份验证且能够执行受影响模板并控制其仓库文件位置的用户,可能导致生成的内容被写入任务工作区之外、且可由 Backstage 后端进程写入的其他位置。该问题已在 0.3.25 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | < 1.54.6 | - |
|
| @backstage | plugin-scaffolder-backend-module-confluence-to-markdown | < 0.3.25 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106558 | 8.8 HIGH | Backstage: Improper validation of TechDocs MkDocs configuration |
| CVE-2026-106510 | 7.7 HIGH | Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml |
| CVE-2026-106556 | 7.7 HIGH | Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization |
| CVE-2026-106559 | 6.3 MEDIUM | Backstage: Improper input validation in Confluence to Markdown scaffolder module |
| CVE-2026-106563 | 5.3 MEDIUM | Backstage: Improper entity validation in deprecated Kubernetes services endpoint |
| CVE-2026-106561 | 5.0 MEDIUM | Backstage: Sensitive information disclosure in Kubernetes resource queries |
| CVE-2026-106562 | 4.3 MEDIUM | Backstage: Incorrect authorization in search engine permission filtering |
No comments yet