Impact
The vulnerability arises from inconsistent enforcement of allowed location types during catalog processing. If an attacker can influence the catalog configuration, the backend may process unexpected location types, potentially reading arbitrary files on the host. This exposes confidential data stored on the backend server.
Affected Systems
The affected products are @backstage:plugin-catalog-backend and backstage:backstage. Any deployment using @backstage/plugin-catalog-backend prior to version 3.9.1 is vulnerable. The fix is available in version 3.9.1 and later; corresponding backstage releases bundle the updated plugin.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity, and the EPSS score is not available. The likely attack vector requires the attacker to supply or influence catalog data that contains disallowed location types; the backend will then access local files. (Inference) In environments where an attacker can tamper with catalog sources, the risk is increased, but a successful exploit still requires configuration access or privileged input.
OpenCVE Enrichment