Vulnerability GHSA-7649-wm97-w3j3
Medium Risk
MEDIUM RISK
CVSS Score: 4.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
October 07, 2026 at 05:59 PM UTC
Backstage: Improper input validation in cloud storage URL readers
0.0.0-nightly-20220811024336 - 0.17.7
0.0.0-nightly-20220811024336 - 0.17.7
Summary
Backstage: Improper input validation in cloud storage URL readers
Details
Impact
An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection.
Patches
Patched in @backstage/backend-defaults version 0.17.8
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
8 months ago
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`
0.0.0-nightly-20220811024336 - 0.12.1 and 0.13.0 - 0.13.1 and 0.14.0 - 0.14.1-next.1 GHSA-q2x5-4xjx-c6p9
0.0.0-nightly-20220811024336 - 0.12.1 and 0.13.0 - 0.13.1 and 0.14.0 - 0.14.1-next.1 GHSA-q2x5-4xjx-c6p9
High Risk
8 months ago
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
0.0.0-nightly-20220811024336 - 0.12.1 and 0.13.0 - 0.13.1 and 0.14.0 - 0.14.1-next.1 GHSA-rq6q-wr2q-7pgp
0.0.0-nightly-20220811024336 - 0.12.1 and 0.13.0 - 0.13.1 and 0.14.0 - 0.14.1-next.1 GHSA-rq6q-wr2q-7pgp
Impacted packages
Timeline
Published
3 hours ago
October 07, 2026 at 05:59 PM UTC
Fixed (0.17.8)
1 month ago
August 28, 2026 at 08:18 AM UTC
Last Modified
3 hours ago
October 07, 2026 at 06:15 PM UTC