Inconsistent Repository Filtering Vulnerability in Backstage Plugin by Spotify
CVE-2026-106458
6.5MEDIUM
What is CVE-2026-106458?
The Backstage framework, specifically the @backstage/plugin-catalog-backend-module-bitbucket-server package, encountered an inconsistency in repository filtering. This issue affects versions from 0.4.0 to 0.5.15, allowing authenticated users to unintentionally trigger repository events even for repositories that should be filtered out based on project and repository settings. As a result, catalog locations could be ingested despite being excluded by the configured filters. To mitigate this vulnerability, users are encouraged to update to version 0.5.15 or later.
Affected Version(s)
backstage >= 1.38.0, < 1.55.0
plugin-catalog-backend-module-bitbucket-server >= 0.4.0, < 0.5.15
