VYPR

Backstage

by Backstage

Source repositories

CVEs (24)

  • CVE-2026-25152MedJan 30, 2026
    risk 0.27cvss 5.3epss 0.00

    Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, a path traversal vulnerability in the TechDocs…

  • CVE-2026-73563MedAug 13, 2026
    risk 0.24cvss 4.7epss 0.00

    Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for…

  • CVE-2025-32791MedApr 16, 2025
    risk 0.21cvss 4.3epss 0.00

    The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permission policy installed…

  • CVE-2025-55285LowAug 15, 2025
    risk 0.10cvss 2.6epss 0.00

    @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly redacted. If ${{…

Page 2 of 2