GHSA-9325-vq29-gp3v

Suggest an improvement
Source
https://github.com/advisories/GHSA-9325-vq29-gp3v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9325-vq29-gp3v/GHSA-9325-vq29-gp3v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9325-vq29-gp3v
Aliases
Published
2026-10-07T18:02:52Z
Modified
2026-10-07T18:15:11Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Backstage has incorrect authorization in search engine permission filtering
Details

Impact

An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.

Patches

  • Upgrade @backstage/plugin-search-backend to 2.1.6
  • Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7

Workarounds

If you are unable to upgrade immediately:

  • Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types
  • Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.
Database specific
{
    "cwe_ids": [
        "CWE-754",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T18:02:52Z",
    "nvd_published_at": "2026-10-07T15:17:17Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @backstage/plugin-search-backend

Package

Name
@backstage/plugin-search-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-search-backend

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9325-vq29-gp3v/GHSA-9325-vq29-gp3v.json"

npm / @backstage/plugin-search-backend-module-elasticsearch

Package

Name
@backstage/plugin-search-backend-module-elasticsearch
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-search-backend-module-elasticsearch

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.8.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9325-vq29-gp3v/GHSA-9325-vq29-gp3v.json"