CVEs we hold for Backstage
Records whose assigning authority named Backstage as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-73563Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in…backstage
CVE-2026-29186@backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Executionbackstage
CVE-2026-29184@backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction Bypassbackstage
CVE-2026-25153@backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooksbackstage
CVE-2026-25152@backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generatorbackstage
CVE-2026-24048Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`backstage
CVE-2026-24047@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypassbackstage
CVE-2025-55285@backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`backstage
CVE-2024-47762Unexpected visibility of environment variable configurations in @backstage/plugin-app-backendbackstage
CVE-2024-46976Circumvention of cross site scripting Protection in @backstage/plugin-techdocs-backendbackstage
26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.