CVE-2026-106496: Backstage: Inconsistent enforcement of allowed location types during catalog processing
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.9.1
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using @backstage/plugin-catalog-backend before version 3.9.1 may be exposed when their catalog configuration relies on allowed location types to restrict what the backend can process. The issue can result in unintended file access on the backend host under certain configurations.
What access does an attacker need?
The supplied vector indicates network reachability, high attack complexity, and low privileges required, with no user interaction required. The data does not specify the particular low-privilege capability needed.
Is a default installation known to be affected?
The issue is described as occurring under certain configurations. The available information does not establish that default configurations are affected.
What is the remediation?
Upgrade @backstage/plugin-catalog-backend to version 3.9.1, which fixes the inconsistent enforcement of allowed location types.