GHSA-qgvj-qcf8-xq73

Suggest an improvement
Source
https://github.com/advisories/GHSA-qgvj-qcf8-xq73
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qgvj-qcf8-xq73/GHSA-qgvj-qcf8-xq73.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qgvj-qcf8-xq73
Aliases
Published
2026-10-07T17:59:24Z
Modified
2026-10-07T18:15:10Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Backstage: Improper URL validation in catalog entity placeholder resolution
Details

Impact

An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user.

Patches

Patched in @backstage/plugin-catalog-backend version 3.9.1

Workarounds

If you're not able to update immediately:

  • Limit the scope of integration credentials (e.g., GitHub tokens) to only the repositories that Backstage needs to access.
Database specific
{
    "cwe_ids": [
        "CWE-863",
        "CWE-918"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T17:59:24Z",
    "nvd_published_at": "2026-10-06T22:17:04Z",
    "severity": "HIGH"
}
References

Affected packages

npm / @backstage/plugin-catalog-backend

Package

Name
@backstage/plugin-catalog-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-catalog-backend

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.9.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qgvj-qcf8-xq73/GHSA-qgvj-qcf8-xq73.json"