CVE-2026-106491: Backstage: Improper input validation in proxy-backend
Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the configured base path on the target server. This is limited to target servers already configured as proxy endpoints and requires Backstage authentication by default. This issue is fixed in version 0.6.17.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-proxy-backendto a version that resolves this vulnerability.Fixed in 0.6.17
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated as a Backstage user. By default, Backstage authentication is required, so unauthenticated users are not exposed through the default access model.
Which systems can an attacker reach through the vulnerable proxy?
The issue is limited to target servers that are already configured as proxy endpoints. It allows requests to paths outside the configured base path on those target servers.
What version fixes the issue?
Upgrade @backstage/plugin-proxy-backend to version 0.6.17 or later. Versions prior to 0.6.17 are affected.