GHSA-9ghw-48h5-v2w5MediumCVSS 6.4

Backstage: Improper input validation in proxy-backend

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the configured base path on the target server. This is limited to target servers already configured as proxy endpoints and requires Backstage authentication by default.

Patches

Patched in @backstage/plugin-proxy-backend version 0.6.17

Workarounds

  • Deploy a reverse proxy or WAF in front of Backstage that normalizes request paths before they reach the backend.

🎯 Affected products1

  • npm/@backstage/plugin-proxy-backend:< 0.6.17

🔗 References (5)