Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qgvj-qcf8-xq73 | Backstage: Improper URL validation in catalog entity placeholder resolution |
Wed, 07 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 06 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1. | |
| Title | Backstage: Improper URL validation in catalog entity placeholder resolution | |
| Weaknesses | CWE-863 CWE-918 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T21:23:37.560Z
Reserved: 2026-10-06T18:46:47.766Z
Link: CVE-2026-106498
No data.
Status : Awaiting Analysis
Published: 2026-10-06T22:17:04.713
Modified: 2026-10-07T13:58:29.527
Link: CVE-2026-106498
OpenCVE Enrichment
Updated: 2026-10-06T23:45:07Z
Github GHSA