Improper URL Validation in Backstage Plugin Catalog Backend
CVE-2026-106498
What is CVE-2026-106498?
The Backstage platform, designed for building developer portals, has a vulnerability in its @backstage/plugin-catalog-backend package that affects multiple versions prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2, and 3.9.1. This vulnerability stems from improper validation of URLs during catalog entity placeholder resolution. An authenticated user can exploit this issue by crafting a catalog entity with placeholder directives, potentially accessing resources outside the entity's designated source repository. This could lead to unauthorized visibility of sensitive data, exposing organizations to increased security risks. The vulnerability has been remediated in the aforementioned versions.
Affected Version(s)
backstage < 1.49.6 < 1.49.6
backstage >= 1.50.0-next.0, < 1.50.5 < 1.50.0-next.0, 1.50.5
backstage >= 1.51.0-next.0, < 1.51.3 < 1.51.0-next.0, 1.51.3
