plugin-catalog-backend vulnerabilities
CVEs whose affected-version data names the plugin-catalog-backend package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-106498High· 7.7⚖ disputedBackstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. …
CVE-2026-106497Medium· 4.3Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based…
CVE-2026-106496Low· 3.1Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain confi…