Improper URL Validation in Backstage Plugin Catalog Backend
CVE-2026-106498

7.7HIGH

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106498?

The Backstage platform, designed for building developer portals, has a vulnerability in its @backstage/plugin-catalog-backend package that affects multiple versions prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2, and 3.9.1. This vulnerability stems from improper validation of URLs during catalog entity placeholder resolution. An authenticated user can exploit this issue by crafting a catalog entity with placeholder directives, potentially accessing resources outside the entity's designated source repository. This could lead to unauthorized visibility of sensitive data, exposing organizations to increased security risks. The vulnerability has been remediated in the aforementioned versions.

Affected Version(s)

backstage < 1.49.6 < 1.49.6

backstage >= 1.50.0-next.0, < 1.50.5 < 1.50.0-next.0, 1.50.5

backstage >= 1.51.0-next.0, < 1.51.3 < 1.51.0-next.0, 1.51.3

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.