GHSA-7649-wm97-w3j3MediumCVSS 4.4
Backstage: Improper input validation in cloud storage URL readers
🔗 CVE IDs covered (1)
📋 Description
Impact
An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection.
Patches
Patched in @backstage/backend-defaults version 0.17.8
🎯 Affected products1
- npm/@backstage/backend-defaults:< 0.17.8
🔗 References (5)
- https://github.com/backstage/backstage/security/advisories/GHSA-7649-wm97-w3j3
- https://nvd.nist.gov/vuln/detail/CVE-2026-106494
- https://github.com/backstage/backstage/commit/14e925ce5b905dd8daa64c3009722febda76034c
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-7649-wm97-w3j3