Description
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.
Published: 2026-10-06
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: File disclosure via unintended backend file access
Action: Patch
AI Analysis

Impact

The vulnerability arises from inconsistent enforcement of allowed location types during catalog processing. If an attacker can influence the catalog configuration, the backend may process unexpected location types, potentially reading arbitrary files on the host. This exposes confidential data stored on the backend server.

Affected Systems

The affected products are @backstage:plugin-catalog-backend and backstage:backstage. Any deployment using @backstage/plugin-catalog-backend prior to version 3.9.1 is vulnerable. The fix is available in version 3.9.1 and later; corresponding backstage releases bundle the updated plugin.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall severity, and the EPSS score is not available. The likely attack vector requires the attacker to supply or influence catalog data that contains disallowed location types; the backend will then access local files. (Inference) In environments where an attacker can tamper with catalog sources, the risk is increased, but a successful exploit still requires configuration access or privileged input.

Generated by OpenCVE AI on October 7, 2026 at 00:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the @backstage/plugin-catalog-backend dependency to version 3.9.1 or later.
  • If using the integrated backstage distribution, upgrade to a release that bundles the fixed plugin, such as v1.54.6 or newer.
  • Validate and restrict catalog location types in your configuration to only approved types before processing.
  • As an interim measure, disable or block external catalog sources that use disallowed location types until the patch can be applied.

Generated by OpenCVE AI on October 7, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.
Title Backstage: Inconsistent enforcement of allowed location types during catalog processing
Weaknesses CWE-22
CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T21:17:11.966Z

Reserved: 2026-10-06T18:46:47.766Z

Link: CVE-2026-106496

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T22:17:04.407

Modified: 2026-10-06T22:17:04.407

Link: CVE-2026-106496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T00:30:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-863

    Incorrect Authorization