Inconsistent Location Type Enforcement in Backstage Plugin by Spotify
CVE-2026-106496
3.1LOW
What is CVE-2026-106496?
The @backstage/plugin-catalog-backend component of the Backstage framework by Spotify is susceptible to a vulnerability due to improper enforcement of permitted location types during catalog processing. This flaw allows for the processing of unauthorized location types under certain configurations, which can result in unintended file access on the backend host. Users are urged to upgrade to version 3.9.1 or later to mitigate this issue and enhance security.
Affected Version(s)
backstage < 1.54.6
plugin-catalog-backend < 3.9.1
