vciy

CVEs we hold for Backstage

Records whose assigning authority named Backstage as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-88064Backstage: Improper input validation in TechDocs MkDocs configurationbackstage
CVE-2026-73563Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in…backstage
CVE-2026-29186@backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Executionbackstage
CVE-2026-29185@backstage/integration: Potential reading of SCM URLs using built in tokenbackstage
CVE-2026-29184@backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction Bypassbackstage
CVE-2026-25153@backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooksbackstage
CVE-2026-25152@backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generatorbackstage
CVE-2026-24048Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`backstage
CVE-2026-24047@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypassbackstage
CVE-2026-24046Backstage has a Possible Symlink Path Traversal in Scaffolder Actionsbackstage
CVE-2025-55285@backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`backstage
CVE-2025-32791Permission policy information leakage in Backstage permission systembackstage
CVE-2024-53983Server-side request forgery in Backstage Scaffolder pluginbackstage
CVE-2024-47762Unexpected visibility of environment variable configurations in @backstage/plugin-app-backendbackstage
CVE-2024-46976Circumvention of cross site scripting Protection in @backstage/plugin-techdocs-backendbackstage
CVE-2024-45816Storage bucket Directory Traversal in @backstage/plugin-techdocs-backendbackstage
CVE-2024-45815Prototype pollution in @backstage/plugin-catalog-backendbackstage
CVE-2024-26150`@backstage/backend-common` vulnerable to path traversal through symlinksbackstage
CVE-2023-35926Insecure sandbox in Backstage Scaffolder pluginbackstage
CVE-2023-25571Backstage has XSS Vulnerability in Software Catalogbackstage
CVE-2021-43783Path Traversal in @backstage/plugin-scaffolder-backendbackstage
CVE-2021-43776XSS vulnerability in @backstage/plugin-auth-backendbackstage
CVE-2021-41151Path Traversal in @backstage/plugin-scaffolder-backendbackstage
CVE-2021-32662TechDocs mkdocs.yml path traversalbackstage
CVE-2021-32661TechDocs object element script injectionbackstage
CVE-2021-32660TechDocs content sanitization bypassbackstage

26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.