GHSA-p7g9-rp3g-mgfg

Suggest an improvement
Source
https://github.com/advisories/GHSA-p7g9-rp3g-mgfg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-p7g9-rp3g-mgfg/GHSA-p7g9-rp3g-mgfg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p7g9-rp3g-mgfg
Aliases
  • CVE-2026-44374
Published
2026-05-06T23:04:07Z
Modified
2026-05-14T21:03:41Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
Details

Impact

The unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module.

Patches

This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30. Users should upgrade all packages.

Workarounds

If users cannot upgrade, they can remove the @backstage/plugin-catalog-backend-module-unprocessed module from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpoints
without upgrading.

Database specific
{
    "cwe_ids":  [
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-06T23:04:07Z",
    "nvd_published_at":  "2026-05-14T15:16:48Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm
@backstage/plugin-catalog-unprocessed-entities-common

Package

Name
@backstage/plugin-catalog-unprocessed-entities-common
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-catalog-unprocessed-entities-common

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.15

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-p7g9-rp3g-mgfg/GHSA-p7g9-rp3g-mgfg.json"
@backstage/plugin-catalog-unprocessed-entities

Package

Name
@backstage/plugin-catalog-unprocessed-entities
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-catalog-unprocessed-entities

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.30

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-p7g9-rp3g-mgfg/GHSA-p7g9-rp3g-mgfg.json"
@backstage/plugin-catalog-backend-module-unprocessed

Package

Name
@backstage/plugin-catalog-backend-module-unprocessed
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-catalog-backend-module-unprocessed

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-p7g9-rp3g-mgfg/GHSA-p7g9-rp3g-mgfg.json"