Where
-Infinity
0

Vendor Risk Score

See how backstage compares to other vendors in security performance

View Risk Score →
Severity
3
Path Traversal
AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

Impact

Catalog entity providers for Azure Blob Storage and AWS S3 did not sufficiently validate storage object paths, which could allow catalog descriptors to be read from outside the intended storage boundary. Access is limited to locations reachable by the backend's configured credentials.

Patches

- @backstage/plugin-catalog-backend-module-azure version 0.3.21 - @backstage/plugin-catalog-backend-module-aws version 0.4.27 - @backstage/backend-defaults version 0.7.18

Workarounds

- Restrict blob and object creation or renaming in configured catalog storage sources to trusted principals. - Scope Backstage's Azure and AWS reader credentials and network access to the intended storage boundaries. - Disable an affected catalog provider if those restrictions cannot be enforced.

1 / 2
Source: GitHub
First published (updated )
Severity
2.6
AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N

@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly redacted. If ${{ secrets.x }} is not passed through to fetch:template there is no impact. This issue has been resolved in 2.1.1 of the scaffolder-backend plugin. A workaround for this issue involves Template Authors removing the use of ${{ secrets }} being used as an argument to fetch:template.

1 / 2
Source: MITRE
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact

A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API.

Patches

This has been fixed in the 1.26.0 release of the @backstage/plugin-catalog-backend package.

References

If you have any questions or comments about this advisory:

Open an issue in the Backstage repository Visit our Discord, linked to in Backstage README

1 / 2
Source: GitHub
First published (updated )
Severity
6.5
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Impact

An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link.

Patches

This has been fixed in the 1.10.13 release of the @backstage/plugin-techdocs-backend package.

References

If you have any questions or comments about this advisory:

Open an issue in the Backstage repository Visit our Discord, linked to in Backstage README

1 / 2
Source: GitHub
First published (updated )
Severity
8.5
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the template in a way that writes files to arbitrary paths on the scaffolder-backend host instance. This vulnerability can in some situation also be exploited through user input when executing a template, meaning you do not need write access to the templates. This method will not allow the attacker to control the contents of the injected file however, unless the template is also crafted in a specific way that gives control of the file contents. This vulnerability is fixed in version 0.15.14 of the @backstage/plugin-scaffolder-backend. This attack is mitigated by restricting access and requiring reviews when registering or modifying scaffolder templates.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203