GHSA-pcmq-25r3-5w9v

Suggest an improvement
Source
https://github.com/advisories/GHSA-pcmq-25r3-5w9v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pcmq-25r3-5w9v/GHSA-pcmq-25r3-5w9v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pcmq-25r3-5w9v
Aliases
Published
2026-10-07T17:59:32Z
Modified
2026-10-07T18:15:13Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Backstage: Inconsistent enforcement of allowed location types during catalog processing
Details

Impact

Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host.

Patches

Patched in @backstage/plugin-catalog-backend version 3.9.1

Workarounds

No practical workarounds are available. Upgrade to the patched version.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T17:59:32Z",
    "nvd_published_at": "2026-10-06T22:17:04Z",
    "severity": "LOW"
}
References

Affected packages

npm / @backstage/plugin-catalog-backend

Package

Name
@backstage/plugin-catalog-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-catalog-backend

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.9.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-pcmq-25r3-5w9v/GHSA-pcmq-25r3-5w9v.json"