GHSA-cq7v-rfgc-5c7v: High severity npm/@backstage/backend-defaults vulnerability

Published Oct 7, 2026
·
Updated

Impact

An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for.

Patches

Patched in @backstage/backend-defaults version 0.17.8

Workarounds

If you're unable to upgrade immediately:

- If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers. - Restrict network-level access to Backstage backend API endpoints to trusted callers only.

Affected Software

1 affected componentFixes available
npm/@backstage/backend-defaults<0.17.8
0.17.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/backend-defaults to a version that resolves this vulnerability.

    Fixed in 0.17.8
  2. Upgrade

    Upgrade @backstage/backend-defaults to a version that resolves this vulnerability.

    Fixed in 0.17.8
  3. Configuration

    If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers.

    credential access restrictions = separate, purpose-specific unrestricted credentials scoped to trusted consumers
  4. Compensating control

    Restrict network-level access to Backstage backend API endpoints to trusted callers only.

Event History

Oct 7, 2026
Advisory Published
via GitHub·05:59 PM
Data Sourced
via GitHub·05:59 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Backstage backend deployments using @backstage/backend-defaults with external service credentials that have access restrictions, such as read-only permissions, are exposed if those credentials can reach plugin delegation paths.

2

What does an attacker need to exploit it?

An attacker needs a restricted external service credential and network access to the relevant Backstage backend API endpoints. No user interaction is required.

3

How can this be remediated?

Upgrade @backstage/backend-defaults to version 0.17.8 or later.

4

What can be done if upgrading is not immediately possible?

Replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers where practical. Restrict network-level access to Backstage backend API endpoints so that only trusted callers can reach them.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203