CVE-2026-73563
- EPSS 0.2%
- Veröffentlicht 13.08.2026 17:32:39
- Zuletzt bearbeitet 13.08.2026 19:17:34
Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching ...
CVE-2026-29186
- EPSS 0.78%
- Veröffentlicht 07.03.2026 15:15:55
- Zuletzt bearbeitet 15.07.2026 02:19:24
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter danger...
CVE-2026-29184
- EPSS 0.26%
- Veröffentlicht 07.03.2026 15:03:18
- Zuletzt bearbeitet 25.04.2026 18:01:46
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in v...
CVE-2026-29185
- EPSS 0.35%
- Veröffentlicht 07.03.2026 15:02:04
- Zuletzt bearbeitet 25.04.2026 18:01:51
Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths. When these UR...
CVE-2026-25152
- EPSS 0.39%
- Veröffentlicht 30.01.2026 21:51:22
- Zuletzt bearbeitet 19.02.2026 15:37:56
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vuln...
CVE-2026-25153
- EPSS 0.54%
- Veröffentlicht 30.01.2026 21:31:58
- Zuletzt bearbeitet 15.07.2026 02:18:52
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when TechDocs is conf...
CVE-2026-24048
- EPSS 0.2%
- Veröffentlicht 21.01.2026 22:51:44
- Zuletzt bearbeitet 25.04.2026 18:01:55
Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0, the `FetchUrlRea...
CVE-2026-24047
- EPSS 0.5%
- Veröffentlicht 21.01.2026 22:45:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility fu...
CVE-2026-24046
- EPSS 0.49%
- Veröffentlicht 21.01.2026 22:36:30
- Zuletzt bearbeitet 15.07.2026 02:18:47
Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates co...
CVE-2025-55285
- EPSS 0.24%
- Veröffentlicht 15.08.2025 17:10:26
- Zuletzt bearbeitet 15.04.2026 00:35:42
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not pro...