Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pcmq-25r3-5w9v | Backstage: Inconsistent enforcement of allowed location types during catalog processing |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1. | |
| Title | Backstage: Inconsistent enforcement of allowed location types during catalog processing | |
| Weaknesses | CWE-22 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T17:06:48.520Z
Reserved: 2026-10-06T18:46:47.766Z
Link: CVE-2026-106496
Updated: 2026-10-07T15:27:10.308Z
Status : Awaiting Analysis
Published: 2026-10-06T22:17:04.407
Modified: 2026-10-07T17:16:49.340
Link: CVE-2026-106496
No data.
OpenCVE Enrichment
Updated: 2026-10-07T00:30:08Z
Github GHSA