Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

backstage — Vulnerabilities & Security Advisories 67

Browse all 67 CVE security advisories affecting backstage. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Backstage is an open-source developer portal platform designed to unify internal developer tools and services under a single interface. Its architecture facilitates service cataloging, documentation, and tool integration, making it a central hub for engineering teams. Security assessments have identified twenty-four Common Vulnerabilities and Exposures (CVEs), primarily stemming from its complex plugin ecosystem and API gateways. Historically, the most prevalent vulnerability classes include Cross-Site Scripting (XSS) and improper access control mechanisms, which often lead to privilege escalation or unauthorized data exposure. While no single catastrophic incident has defined its history, the accumulation of these flaws highlights risks associated with third-party plugin dependencies and insufficient input validation. Organizations deploying this solution must prioritize rigorous plugin auditing and strict role-based access controls to mitigate the inherent risks of its extensible framework.

Top products by backstage: backstage
CVE ID Title CVSS Severity Published
CVE-2026-106487 Backstage: Unsupported catalog cluster authentication mode in kubernetes backend — backstage CWE-441 3.5 Low 2026-10-06
CVE-2026-106486 Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions — backstage CWE-22 8.5 High 2026-10-06
CVE-2026-106463 Backstage: Improper authorization in GitLab organizational user ingestion — backstage CWE-863 5.4 Medium 2026-10-06
CVE-2026-106462 Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallback — backstage CWE-441 6.4 Medium 2026-10-06
CVE-2026-106461 Backstage: Incorrect authorization in scaffolder task listing — backstage CWE-863 4.3 Medium 2026-10-06
CVE-2026-106460 Backstage: Explicit negative email verification can be ignored during shared OAuth profile normalization — backstage CWE-287 6.8 Medium 2026-10-06
CVE-2026-106459 Backstage: Improper input validation in Sentry scaffolder actions — backstage CWE-200 8.5 High 2026-10-06
CVE-2026-106458 Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates — backstage CWE-863 6.5 Medium 2026-10-06
CVE-2026-106457 Backstage: Insufficient audience validation in the Cloudflare Access auth provider — backstage CWE-287 6.8 Medium 2026-10-06
CVE-2026-106456 Backstage: Inconsistent credential enforcement for overlapping proxy routes — backstage CWE-863 4.8 Medium 2026-10-06
CVE-2026-106455 Backstage: Improper validation of MkDocs plugin configuration in TechDocs — backstage CWE-918 7.7 High 2026-10-06
CVE-2026-88064 Backstage: Improper input validation in TechDocs MkDocs configuration — backstage CWE-20 8.8 High 2026-09-16
CVE-2026-73563 Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend` — backstage CWE-601 4.7 Medium 2026-08-13
CVE-2026-29186 @backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution — backstage CWE-434 7.7 High 2026-03-07
CVE-2026-29184 @backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction Bypass — backstage CWE-532 2.0 Low 2026-03-07
CVE-2026-29185 @backstage/integration: Potential reading of SCM URLs using built in token — backstage CWE-22 2.7 Low 2026-03-07
CVE-2026-25152 @backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator — backstage CWE-22 5.3 Medium 2026-01-30
CVE-2026-25153 @backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks — backstage CWE-94 7.7 High 2026-01-30
CVE-2026-24048 Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow` — backstage CWE-918 3.5 Low 2026-01-21
CVE-2026-24047 @backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass — backstage CWE-59 6.3 Medium 2026-01-21
CVE-2026-24046 Backstage has a Possible Symlink Path Traversal in Scaffolder Actions — backstage CWE-22 7.1 High 2026-01-21
CVE-2025-55285 @backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template` — backstage CWE-532 2.6 Low 2025-08-15
CVE-2025-32791 Permission policy information leakage in Backstage permission system — backstage CWE-213 4.3 Medium 2025-04-16
CVE-2024-53983 Server-side request forgery in Backstage Scaffolder plugin — backstage CWE-918 5.4 Medium 2024-11-29
CVE-2024-47762 Unexpected visibility of environment variable configurations in @backstage/plugin-app-backend — backstage CWE-440 5.8 Medium 2024-10-03
CVE-2024-45815 Prototype pollution in @backstage/plugin-catalog-backend — backstage CWE-1321 6.5 Medium 2024-09-17
CVE-2024-45816 Storage bucket Directory Traversal in @backstage/plugin-techdocs-backend — backstage CWE-23 6.5 Medium 2024-09-17
CVE-2024-46976 Circumvention of cross site scripting Protection in @backstage/plugin-techdocs-backend — backstage CWE-693 6.5 Medium 2024-09-17
CVE-2024-26150 `@backstage/backend-common` vulnerable to path traversal through symlinks — backstage CWE-22 8.7 High 2024-02-23
CVE-2023-35926 Insecure sandbox in Backstage Scaffolder plugin — backstage CWE-94 8.1 High 2023-06-22

This page lists every published CVE security advisory associated with backstage. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.