backstage vulnerabilities
CVEs whose affected-version data names the backstage package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-88064High· 8.8Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can regist…
▾ Twilightbackstage · backstageEPSS 0.63%via NVD
CVE-2026-25153High· 7.7Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when Tec…
▾ Twilightlinuxfoundation · backstageEPSS 0.57%via NVD