VendorsLinux Foundationbackstageany version
Vulnerabilities

Linux Foundation The Linux Foundation Backstage any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2023-35926
Insecure sandbox in Backstage Scaffolder plugin
Published 2023-06-22 · Modified
9.9EPSS 0.019
CVE-2026-25153
@backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks
Published 2026-01-30 · Modified
8.8EPSS 0.006
CVE-2021-43783
Path Traversal in @backstage/plugin-scaffolder-backend
Published 2021-11-29 · Analyzed
8.5EPSS 0.012
CVE-2026-32236
@backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch
Published 2026-03-12 · Modified
7.5EPSS 0.003
CVE-2021-41151
Path Traversal in @backstage/plugin-scaffolder-backend
Published 2021-10-18 · Modified
6.8EPSS 0.013
CVE-2021-32662
TechDocs mkdocs.yml path traversal
Published 2021-06-03 · Modified
6.5EPSS 0.013
CVE-2024-45816
Storage bucket Directory Traversal in @backstage/plugin-techdocs-backend
Published 2024-09-17 · Analyzed
6.5EPSS 0.007
CVE-2024-45815
Prototype pollution in @backstage/plugin-catalog-backend
Published 2024-09-17 · Analyzed
6.5EPSS 0.005
CVE-2026-25152
@backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator
Published 2026-01-30 · Analyzed
6.5EPSS 0.004
CVE-2024-46976
Circumvention of cross site scripting Protection in @backstage/plugin-techdocs-backend
Published 2024-09-17 · Analyzed
6.5EPSS 0.003
CVE-2026-32235
@backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass
Published 2026-03-12 · Analyzed
5.9EPSS 0.001
CVE-2023-6944
Rhdh: catalog-import function leaks credentials to frontend
Published 2024-01-04 · Modified
5.7EPSS 0.006