VYPR
advisoryPublished Oct 7, 2026· Updated Oct 8, 2026· 1 source

Backstage: 25 Vulnerabilities Disclosed in Coordinated Batch Affecting Key Plugins

Key findings • 25 vulnerabilities disclosed for Backstage across multiple plugins between October 6-7, 2026. • Critical and High severity flaws found in scaffolder and techdocs plugins, impac…

Key findings

  • 25 vulnerabilities disclosed for Backstage across multiple plugins between October 6-7, 2026.
  • Critical and High severity flaws found in scaffolder and techdocs plugins, impacting authorization and data exposure.
  • Affected plugins include @backstage/plugin-techdocs-node, @backstage/plugin-scaffolder-backend, and @backstage/plugin-kubernetes-backend.
  • Patches are available for various versions, with users urged to update promptly.
  • Vulnerabilities primarily affect authenticated users, allowing bypass of restrictions and access to sensitive information.

On October 6-7, 2026, a significant batch of 25 vulnerabilities was disclosed for Backstage, an open framework for building developer portals. These vulnerabilities, spanning multiple components and ranging in severity from Low to Critical, were disclosed together, indicating a coordinated disclosure event. The vulnerabilities primarily affect the scaffolder, techdocs, kubernetes, and catalog backend plugins, with several allowing authenticated users to bypass intended restrictions, access sensitive information, or manipulate documentation builds.

The @backstage/plugin-techdocs-node package is implicated in several high-severity flaws (CVE-2026-106557, CVE-2026-106556, CVE-2026-106509). These vulnerabilities stem from insufficient validation of TechDocs Markdown extension configurations, MkDocs theme configurations, and sanitization of mkdocs.yml files. Exploiting these could allow an authenticated user to access resources or bypass security controls during documentation generation. CVE-2026-106558, also affecting @backstage/plugin-techdocs-node, involves improper validation of mapping-style markdown_extensions, potentially allowing bypass of TechDocs security.

Several vulnerabilities in the @backstage/plugin-scaffolder-backend package were disclosed, with CVE-2026-106503 (High, CVSSv3 8.1) and CVE-2026-106501 (Critical, CVSSv3 9.6) being particularly concerning. These relate to scaffolder action input authorization bypass and sensitive information exposure in scaffolder tasks, respectively. Other scaffolder-related issues include improper repository path validation (CVE-2026-106560), input validation in confluence to markdown conversion (CVE-2026-106559), sensitive information exposure in task logs (CVE-2026-106504), and exposure of sensitive information in task failure events (CVE-2026-106502). CVE-2026-106500 and CVE-2026-106499 also highlight issues with task state validation and secret-derived values in task logs.

The @backstage/plugin-kubernetes-backend package is affected by improper entity validation (CVE-2026-106563) and sensitive information disclosure in resource queries (CVE-2026-106561), allowing authenticated users to access data beyond their permissions.

The @backstage/plugin-catalog-backend package has several vulnerabilities, including improper URL validation in entity placeholder resolution (CVE-2026-106498), inconsistent permission evaluation (CVE-2026-106497), and inconsistent enforcement of allowed location types (CVE-2026-106496).

Other affected components include @backstage/backend-defaults, with vulnerabilities in cloud storage URL readers (CVE-2026-106494) and improper preservation of access restrictions during credential delegation (CVE-2026-106492). The @backstage/plugin-proxy-backend is affected by improper input validation (CVE-2026-106491).

The disclosed vulnerabilities were patched in various versions. For @backstage/plugin-techdocs-node, fixes are available in versions 1.14.6, 1.14.8, 1.15.4, and 1.15.6. The @backstage/plugin-scaffolder-backend was patched in versions 3.3.1, 3.4.1, 4.0.3, and 4.1.0. The @backstage/plugin-catalog-backend received fixes in versions 3.3.1, 3.4.1, 3.5.1, 3.6.2, 3.7.2, 3.8.2, 3.9.1, and 4.1.0. Users are advised to update to the patched versions to mitigate these risks.

This batch of vulnerabilities underscores the importance of regularly updating Backstage instances and its plugins. The wide range of affected components and the severity of some flaws highlight potential attack vectors for authenticated users within a Backstage deployment. Staying current with patches is crucial for maintaining the security and integrity of developer portals built with Backstage.

Synthesized by Vypr AI