Low severity3.1NVD Advisory· Published Oct 6, 2026
CVE-2026-106496
CVE-2026-106496
Description
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <3.9.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.