GHSA-7649-wm97-w3j3

Suggest an improvement
Source
https://github.com/advisories/GHSA-7649-wm97-w3j3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-7649-wm97-w3j3/GHSA-7649-wm97-w3j3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7649-wm97-w3j3
Aliases
Published
2026-10-07T17:59:38Z
Modified
2026-10-07T18:15:12Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Backstage: Improper input validation in cloud storage URL readers
Details

Impact

An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection.

Patches

Patched in @backstage/backend-defaults version 0.17.8

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-73"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T17:59:38Z",
    "nvd_published_at": "2026-10-06T21:17:18Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @backstage/backend-defaults

Package

Name
@backstage/backend-defaults
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/backend-defaults

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.17.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-7649-wm97-w3j3/GHSA-7649-wm97-w3j3.json"