Vulnerability GHSA-7mfx-xg57-53c9
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
October 07, 2026 at 06:00 PM UTC
Backstage: Improper input validation in TechDocs static content requests
0.0.0-nightly-20201012104 - 2.2.3
0.0.0-nightly-20201012104 - 2.2.3
Summary
Backstage: Improper input validation in TechDocs static content requests
Details
Impact
When using the Azure Blob Storage provider, an authenticated Backstage user may be able to read restricted TechDocs content when entity-level permissions are enabled. Deployments that intentionally disable the default backend authentication policy may have broader exposure.
Patches
Patched in @backstage/plugin-techdocs-backend version 2.2.4
Workarounds
- Restrict access to the TechDocs backend to users who are permitted to view all stored documentation until an upgrade can be applied.
- Keep the default backend authentication policy enabled.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 hours ago
Backstage: Improper authorization enforcement for TechDocs static content
0.0.0-nightly-20201012104 - 2.2.3 GHSA-rg9r-hr7g-5gc2
0.0.0-nightly-20201012104 - 2.2.3 GHSA-rg9r-hr7g-5gc2
Medium Risk
2 years ago
@backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection
0.0.0-nightly-20201012104 - 1.10.13-next.2 GHSA-5j94-f3mf-8685
0.0.0-nightly-20201012104 - 1.10.13-next.2 GHSA-5j94-f3mf-8685
High Risk
2 years ago
@backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability
0.0.0-nightly-20201012104 - 1.10.13-next.2 GHSA-39v3-f278-vj3g
0.0.0-nightly-20201012104 - 1.10.13-next.2 GHSA-39v3-f278-vj3g
Impacted packages
Timeline
Published
3 hours ago
October 07, 2026 at 06:00 PM UTC
Fixed (2.2.4)
1 month ago
August 28, 2026 at 08:21 AM UTC
Last Modified
3 hours ago
October 07, 2026 at 06:15 PM UTC