CVE-2026-106498: Backstage: Improper URL validation in catalog entity placeholder resolution
### Impact An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. ### Patches Patched in `@backstage/plugin-catalog-backend` version `3.9.1` ### Workarounds If you're not able to update immediately: - Limit the scope of integration credentials (e.g., GitHub tokens) to only the repositories that Backstage needs to access.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/plugin-catalog-backend 3.9.1.
Technical details
- Vendor
- Not specified
- Product
- @backstage/plugin-catalog-backend
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source