GHSA-7mfx-xg57-53c9MediumCVSS 6.5

Backstage: Improper input validation in TechDocs static content requests

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When using the Azure Blob Storage provider, an authenticated Backstage user may be able to read restricted TechDocs content when entity-level permissions are enabled. Deployments that intentionally disable the default backend authentication policy may have broader exposure.

Patches

Patched in @backstage/plugin-techdocs-backend version 2.2.4

Workarounds

  • Restrict access to the TechDocs backend to users who are permitted to view all stored documentation until an upgrade can be applied.
  • Keep the default backend authentication policy enabled.

🎯 Affected products1

  • npm/@backstage/plugin-techdocs-backend:< 2.2.4

🔗 References (5)