Vulnerability GHSA-pcmq-25r3-5w9v

Low Risk
LOW RISK
CVSS Score: 3.1
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
3 hours ago
October 07, 2026 at 05:59 PM UTC
Backstage: Inconsistent enforcement of allowed location types during catalog processing
0.0.0-nightly-20201012104 - 3.9.0
0.0.0-nightly-20201012104 - 3.9.0

Summary

Backstage: Inconsistent enforcement of allowed location types during catalog processing

Details

Impact

Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host.

Patches

Patched in @backstage/plugin-catalog-backend version 3.9.1

Workarounds

No practical workarounds are available. Upgrade to the patched version.

Timeline

Published
3 hours ago
October 07, 2026 at 05:59 PM UTC
Fixed (3.9.1)
1 month ago
August 28, 2026 at 08:18 AM UTC
Last Modified
3 hours ago
October 07, 2026 at 06:15 PM UTC