An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user.
Patched in @backstage/plugin-catalog-backend version 3.9.1
If you're not able to update immediately:
{
"cwe_ids": [
"CWE-863",
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T17:59:24Z",
"nvd_published_at": "2026-10-06T22:17:04Z",
"severity": "HIGH"
}