Improper Input Validation in Backstage Plugin Proxy Backend
CVE-2026-106491

6.4MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106491?

The @backstage/plugin-proxy-backend package prior to version 0.6.17 contains a vulnerability due to improper input validation. An authenticated user of Backstage could potentially craft a specially designed request URL, which could mislead the proxy-backend into sending the request to an unauthorized location beyond the established base path on the intended server. This vulnerability is applicable primarily to servers that are already configured as proxy endpoints and necessitates prior authentication within the Backstage platform. The issue has been addressed and resolved in version 0.6.17.

Affected Version(s)

backstage < 1.54.6

plugin-proxy-backend < 0.6.17

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.