An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection.
Patched in @backstage/backend-defaults version 0.17.8
{
"cwe_ids": [
"CWE-22",
"CWE-73"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T17:59:38Z",
"nvd_published_at": "2026-10-06T21:17:18Z",
"severity": "MODERATE"
}