GHSA-qgvj-qcf8-xq73HighCVSS 7.7

Backstage: Improper URL validation in catalog entity placeholder resolution

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user.

Patches

Patched in @backstage/plugin-catalog-backend version 3.9.1

Workarounds

If you're not able to update immediately:

  • Limit the scope of integration credentials (e.g., GitHub tokens) to only the repositories that Backstage needs to access.

🎯 Affected products1

  • npm/@backstage/plugin-catalog-backend:< 3.9.1

🔗 References (13)