VYPR

@backstage/backend-defaults

by Backstage

CVEs (2)

  • CVE-2026-106492HigOct 6, 2026
    risk 0.42cvss 7.6epss —

    Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with…

  • CVE-2026-106494MedOct 6, 2026
    risk 0.22cvss 4.4epss —

    Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud storage bucket used by Backstage could craft…