Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

backstage — Vulnerabilities & Security Advisories 67

All 67 CVE vulnerabilities found in backstage, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for the open-source developer portal, Backstage, developed by Spotify. The collection focuses on security weaknesses affecting the application server, plugin system, and its underlying components, covering reported issues from 2021 through the present. Readers can use this index to track the vendor’s security advisories, understand recurring weakness classes such as cross-site scripting or dependency flaws, and examine the specific vulnerability history associated with Backstage releases. By organizing data by product, you can identify patterns in how new versions address past defects and assess the risk profile of the current deployment. The entries summarize each defect with its classification, impact, and recommended remediation steps, providing a consolidated view of the project’s security posture over time.

Vendor: backstage

CVE ID Title CVSS Severity Published
CVE-2026-106487 Backstage: Unsupported catalog cluster authentication mode in kubernetes backend CWE-441 3.5 Low 2026-10-06
CVE-2026-106486 Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions CWE-22 8.5 High 2026-10-06
CVE-2026-106463 Backstage: Improper authorization in GitLab organizational user ingestion CWE-863 5.4 Medium 2026-10-06
CVE-2026-106462 Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallback CWE-441 6.4 Medium 2026-10-06
CVE-2026-106461 Backstage: Incorrect authorization in scaffolder task listing CWE-863 4.3 Medium 2026-10-06
CVE-2026-106460 Backstage: Explicit negative email verification can be ignored during shared OAuth profile normalization CWE-287 6.8 Medium 2026-10-06
CVE-2026-106459 Backstage: Improper input validation in Sentry scaffolder actions CWE-200 8.5 High 2026-10-06
CVE-2026-106458 Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates CWE-863 6.5 Medium 2026-10-06
CVE-2026-106457 Backstage: Insufficient audience validation in the Cloudflare Access auth provider CWE-287 6.8 Medium 2026-10-06
CVE-2026-106456 Backstage: Inconsistent credential enforcement for overlapping proxy routes CWE-863 4.8 Medium 2026-10-06
CVE-2026-106455 Backstage: Improper validation of MkDocs plugin configuration in TechDocs CWE-918 7.7 High 2026-10-06
CVE-2026-88064 Backstage: Improper input validation in TechDocs MkDocs configuration CWE-20 8.8 High 2026-09-16
CVE-2026-73563 Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend` CWE-601 4.7 Medium 2026-08-13
CVE-2026-29186 @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution CWE-434 7.7 High 2026-03-07
CVE-2026-29184 @backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction Bypass CWE-532 2.0 Low 2026-03-07
CVE-2026-29185 @backstage/integration: Potential reading of SCM URLs using built in token CWE-22 2.7 Low 2026-03-07
CVE-2026-25152 @backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator CWE-22 5.3 Medium 2026-01-30
CVE-2026-25153 @backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks CWE-94 7.7 High 2026-01-30
CVE-2026-24048 Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow` CWE-918 3.5 Low 2026-01-21
CVE-2026-24047 @backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass CWE-59 6.3 Medium 2026-01-21
CVE-2026-24046 Backstage has a Possible Symlink Path Traversal in Scaffolder Actions CWE-22 7.1 High 2026-01-21
CVE-2025-55285 @backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template` CWE-532 2.6 Low 2025-08-15
CVE-2025-32791 Permission policy information leakage in Backstage permission system CWE-213 4.3 Medium 2025-04-16
CVE-2024-53983 Server-side request forgery in Backstage Scaffolder plugin CWE-918 5.4 Medium 2024-11-29
CVE-2024-47762 Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend CWE-440 5.8 Medium 2024-10-03
CVE-2024-45815 Prototype pollution in @backstage/plugin-catalog-backend CWE-1321 6.5 Medium 2024-09-17
CVE-2024-45816 Storage bucket Directory Traversal in @backstage/plugin-techdocs-backend CWE-23 6.5 Medium 2024-09-17
CVE-2024-46976 Circumvention of cross site scripting Protection in @backstage/plugin-techdocs-backend CWE-693 6.5 Medium 2024-09-17
CVE-2024-26150 `@backstage/backend-common` vulnerable to path traversal through symlinks CWE-22 8.7 High 2024-02-23
CVE-2023-35926 Insecure sandbox in Backstage Scaffolder plugin CWE-94 8.1 High 2023-06-22

All 67 known CVE vulnerabilities affecting backstage with full Chinese analysis, references, and POCs where available.