CVE-2026-106496Low· 3.1▾ SunlitBackstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain confi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106508Medium· 5.3Backstage is an open framework for building developer portals
CVE-2026-106497Medium· 4.3Backstage is an open framework for building developer portals
CVE-2026-106498High· 7.7Backstage is an open framework for building developer portals
CVE-2026-106494Medium· 4.4Backstage is an open framework for building developer portals
CVE-2026-106491Medium· 6.4Backstage is an open framework for building developer portals
CVE-2026-106492High· 7.6Backstage is an open framework for building developer portals