---
id: CVE-2026-106494
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. Prior to
  0.17.8, the @backstage/backend-defaults package is affected by improper input
  validation in cloud storage url readers. An attacker with write access to a
  cloud stora…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-22
  - CWE-73
vendor: backstage
product: backstage
affected:
  - backstage < 1.54.6
  - backend-defaults < 0.17.8
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:18.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106494'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/14e925ce5b905dd8daa64c3009722febda76034c
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.54.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-7649-wm97-w3j3
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T21:20:28.986Z'
---

## Overview

Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection. This issue is fixed in version 0.17.8.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
