Vulnerability GHSA-pcmq-25r3-5w9v
Low Risk
LOW RISK
CVSS Score: 3.1
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
3 hours ago
October 07, 2026 at 05:59 PM UTC
Backstage: Inconsistent enforcement of allowed location types during catalog processing
0.0.0-nightly-20201012104 - 3.9.0
0.0.0-nightly-20201012104 - 3.9.0
Summary
Backstage: Inconsistent enforcement of allowed location types during catalog processing
Details
Impact
Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host.
Patches
Patched in @backstage/plugin-catalog-backend version 3.9.1
Workarounds
No practical workarounds are available. Upgrade to the patched version.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
2 years ago
@backstage/plugin-catalog-backend Prototype Pollution vulnerability
0.0.0-nightly-20201012104 - 1.26.0-next.2 GHSA-3x3f-jcp3-g22j
0.0.0-nightly-20201012104 - 1.26.0-next.2 GHSA-3x3f-jcp3-g22j
Medium Risk
3 years ago
Cross site scripting Vulnerability in backstage Software Catalog
0.0.0-nightly-20201012104 - 1.7.2-next.2 GHSA-7hv8-3fr9-j2hv
0.0.0-nightly-20201012104 - 1.7.2-next.2 GHSA-7hv8-3fr9-j2hv
Impacted packages
Timeline
Published
3 hours ago
October 07, 2026 at 05:59 PM UTC
Fixed (3.9.1)
1 month ago
August 28, 2026 at 08:18 AM UTC
Last Modified
3 hours ago
October 07, 2026 at 06:15 PM UTC