Improper Input Validation in Backstage Plugin Proxy Backend
CVE-2026-106491
6.4MEDIUM
What is CVE-2026-106491?
The @backstage/plugin-proxy-backend package prior to version 0.6.17 contains a vulnerability due to improper input validation. An authenticated user of Backstage could potentially craft a specially designed request URL, which could mislead the proxy-backend into sending the request to an unauthorized location beyond the established base path on the intended server. This vulnerability is applicable primarily to servers that are already configured as proxy endpoints and necessitates prior authentication within the Backstage platform. The issue has been addressed and resolved in version 0.6.17.
Affected Version(s)
backstage < 1.54.6
plugin-proxy-backend < 0.6.17
