GHSA-qgvj-qcf8-xq73HighCVSS 7.7
Backstage: Improper URL validation in catalog entity placeholder resolution
🔗 CVE IDs covered (1)
📋 Description
Impact
An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user.
Patches
Patched in @backstage/plugin-catalog-backend version 3.9.1
Workarounds
If you're not able to update immediately:
- Limit the scope of integration credentials (e.g., GitHub tokens) to only the repositories that Backstage needs to access.
🎯 Affected products1
- npm/@backstage/plugin-catalog-backend:< 3.9.1
🔗 References (13)
- https://github.com/backstage/backstage/security/advisories/GHSA-qgvj-qcf8-xq73
- https://nvd.nist.gov/vuln/detail/CVE-2026-106498
- https://github.com/backstage/backstage/commit/0b0f6fc89b4eb4872c76a498abbe1dc65998bb6e
- https://github.com/backstage/backstage/commit/286bfc1f9cc3608a073b41016be302785be385d1
- https://github.com/backstage/backstage/commit/61a10f19926aeda7f4a32de48d733e6710584634
- https://github.com/backstage/backstage/commit/99729e925fd2bd40ba210022351a0ee6318e6197
- https://github.com/backstage/backstage/commit/e786ac309ed2d775daf2309393c015c43902d6f6
- https://github.com/backstage/backstage/releases/tag/v1.49.6
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.51.3
- https://github.com/backstage/backstage/releases/tag/v1.53.2
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-qgvj-qcf8-xq73