Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

backstage — Vulnerabilities & Security Advisories 67

All 67 CVE vulnerabilities found in backstage, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for the open-source developer portal, Backstage, developed by Spotify. The collection focuses on security weaknesses affecting the application server, plugin system, and its underlying components, covering reported issues from 2021 through the present. Readers can use this index to track the vendor’s security advisories, understand recurring weakness classes such as cross-site scripting or dependency flaws, and examine the specific vulnerability history associated with Backstage releases. By organizing data by product, you can identify patterns in how new versions address past defects and assess the risk profile of the current deployment. The entries summarize each defect with its classification, impact, and recommended remediation steps, providing a consolidated view of the project’s security posture over time.

Vendor: backstage

CVE ID Title CVSS Severity Published
CVE-2026-106557 Backstage: Improper input validation in TechDocs Markdown extension configuration CWE-22 7.7 High 2026-10-07
CVE-2026-106563 Backstage: Improper entity validation in deprecated Kubernetes services endpoint CWE-20 5.3 Medium 2026-10-07
CVE-2026-106562 Backstage: Incorrect authorization in search engine permission filtering CWE-754 4.3 Medium 2026-10-07
CVE-2026-106561 Backstage: Sensitive information disclosure in Kubernetes resource queries CWE-200 5.0 Medium 2026-10-07
CVE-2026-106560 Backstage: Improper repository path validation in a Scaffolder backend module CWE-22 7.1 High 2026-10-07
CVE-2026-106559 Backstage: Improper input validation in Confluence to Markdown scaffolder module CWE-22 6.3 Medium 2026-10-07
CVE-2026-106558 Backstage: Improper validation of TechDocs MkDocs configuration CWE-502 8.8 High 2026-10-07
CVE-2026-106556 Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization CWE-78 7.7 High 2026-10-07
CVE-2026-106510 Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml CWE-183 7.7 High 2026-10-07
CVE-2026-106509 Backstage: Improper validation of MkDocs theme configuration in TechDocs CWE-94 7.7 High 2026-10-06
CVE-2026-106508 Backstage: Potential file exposure through local TechDocs publisher CWE-22 5.3 Medium 2026-10-06
CVE-2026-106507 Backstage: TechDocs arbitrary file read via mkdocs snippets CWE-59 5.3 Medium 2026-10-06
CVE-2026-106506 Backstage: Improper input validation in scaffolder task list ordering CWE-202 5.3 Medium 2026-10-06
CVE-2026-106505 Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend CWE-426 7.7 High 2026-10-06
CVE-2026-106504 Backstage: Sensitive information exposure in scaffolder task logs CWE-532 6.5 Medium 2026-10-06
CVE-2026-106503 Backstage: Scaffolder action input authorization bypass CWE-178 8.1 High 2026-10-06
CVE-2026-106502 Backstage: Sensitive information may be exposed in Scaffolder task failure events CWE-532 5.3 Medium 2026-10-06
CVE-2026-106501 Backstage: Sensitive information exposure in Scaffolder CWE-200 9.6 Critical 2026-10-06
CVE-2026-106500 Backstage: Improper task state validation in Scaffolder backend CWE-59 8.5 High 2026-10-06
CVE-2026-106499 Backstage: Secret-derived values may be exposed in scaffolder task logs CWE-532 4.9 Medium 2026-10-06
CVE-2026-106498 Backstage: Improper URL validation in catalog entity placeholder resolution CWE-863 7.7 High 2026-10-06
CVE-2026-106497 Backstage: Inconsistent catalog property permission evaluation CWE-178 4.3 Medium 2026-10-06
CVE-2026-106496 Backstage: Inconsistent enforcement of allowed location types during catalog processing CWE-22 3.1 Low 2026-10-06
CVE-2026-106494 Backstage: Improper input validation in cloud storage URL readers CWE-22 4.4 Medium 2026-10-06
CVE-2026-106493 Backstage: Cloud storage catalog locations may cross configured storage boundaries CWE-22 3.0 Low 2026-10-06
CVE-2026-106492 Backstage: Improper preservation of access restrictions during service credential delegation CWE-269 7.6 High 2026-10-06
CVE-2026-106491 Backstage: Improper input validation in proxy-backend CWE-20 6.4 Medium 2026-10-06
CVE-2026-106490 Backstage: Improper input validation in TechDocs static content requests CWE-22 6.5 Medium 2026-10-06
CVE-2026-106489 Backstage: Improper authorization enforcement for TechDocs static content CWE-22 6.5 Medium 2026-10-06
CVE-2026-106488 Backstage: Improper authentication in the OIDC provider CWE-287 8.1 High 2026-10-06

All 67 known CVE vulnerabilities affecting backstage with full Chinese analysis, references, and POCs where available.