GHSA-7649-wm97-w3j3MediumCVSS 4.4

Backstage: Improper input validation in cloud storage URL readers

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection.

Patches

Patched in @backstage/backend-defaults version 0.17.8

🎯 Affected products1

  • npm/@backstage/backend-defaults:< 0.17.8

🔗 References (5)