CVE-2026-106498: Backstage: Improper URL validation in catalog entity placeholder resolution
Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.5.1 - Upgrade
Upgrade
@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.6.2 - Upgrade
Upgrade
@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.7.2 - Upgrade
Upgrade
@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.8.2 - Upgrade
Upgrade
@backstage/plugin-catalog-backendto a version that resolves this vulnerability.Fixed in 3.9.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Backstage user who can craft a catalog entity containing placeholder directives can attempt exploitation. Exposure depends on configurations where those directives can retrieve resources outside the entity's source repository.
Which versions contain the fix?
The issue is fixed in @backstage/plugin-catalog-backend versions 3.5.1, 3.6.2, 3.7.2, 3.8.2, and 3.9.1. Versions prior to those releases are affected.
What is the potential impact?
Under certain configurations, placeholder resolution may let an authenticated user access data that was not intended to be available to them. The vulnerability concerns references to resources outside the catalog entity's source repository.