Improper Input Validation in Backstage's Cloud Storage URL Readers
CVE-2026-106494
4.4MEDIUM
What is CVE-2026-106494?
The @backstage/backend-defaults package in Backstage is susceptible to an improper input validation vulnerability that affects cloud storage URL readers. If an attacker gains write access to a cloud storage bucket utilized by Backstage, they can manipulate object names to collide with reserved files in the output directory. This flaw poses a threat of content injection in certain deployment configurations. The issue has been addressed in version 0.17.8, emphasizing the importance of updating to mitigate potential risks.
Affected Version(s)
backend-defaults < 0.17.8
backstage < 1.54.6
