Improper Input Validation in Backstage's Cloud Storage URL Readers
CVE-2026-106494

4.4MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106494?

The @backstage/backend-defaults package in Backstage is susceptible to an improper input validation vulnerability that affects cloud storage URL readers. If an attacker gains write access to a cloud storage bucket utilized by Backstage, they can manipulate object names to collide with reserved files in the output directory. This flaw poses a threat of content injection in certain deployment configurations. The issue has been addressed in version 0.17.8, emphasizing the importance of updating to mitigate potential risks.

Affected Version(s)

backend-defaults < 0.17.8

backstage < 1.54.6

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.