OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-106498: Backstage: Improper URL validation in catalog entity placeholder resolution

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

### Impact An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. ### Patches Patched in `@backstage/plugin-catalog-backend` version `3.9.1` ### Workarounds If you're not able to update immediately: - Limit the scope of integration credentials (e.g., GitHub tokens) to only the repositories that Backstage needs to access.

Upgrade affected packages to a patched version: @backstage/plugin-catalog-backend 3.9.1.

Vendor
Not specified
Product
@backstage/plugin-catalog-backend
Exploitation
none known
Evidence
official
CVSS
7.7

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source