GHSA-7mfx-xg57-53c9MediumCVSS 6.5
Backstage: Improper input validation in TechDocs static content requests
🔗 CVE IDs covered (1)
📋 Description
Impact
When using the Azure Blob Storage provider, an authenticated Backstage user may be able to read restricted TechDocs content when entity-level permissions are enabled. Deployments that intentionally disable the default backend authentication policy may have broader exposure.
Patches
Patched in @backstage/plugin-techdocs-backend version 2.2.4
Workarounds
- Restrict access to the TechDocs backend to users who are permitted to view all stored documentation until an upgrade can be applied.
- Keep the default backend authentication policy enabled.
🎯 Affected products1
- npm/@backstage/plugin-techdocs-backend:< 2.2.4
🔗 References (5)
- https://github.com/backstage/backstage/security/advisories/GHSA-7mfx-xg57-53c9
- https://nvd.nist.gov/vuln/detail/CVE-2026-106490
- https://github.com/backstage/backstage/commit/40ecc4c2e88b0218125b0a3405d1f6315b321974
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-7mfx-xg57-53c9