Backstage: Improper input validation in cloud storage URL readers
Moderate severity
GitHub Reviewed
Published
Aug 28, 2026
in
backstage/backstage
•
Updated Oct 7, 2026
Description
Published by the National Vulnerability Database
Oct 6, 2026
Published to the GitHub Advisory Database
Oct 7, 2026
Reviewed
Oct 7, 2026
Last updated
Oct 7, 2026
Impact
An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection.
Patches
Patched in
@backstage/backend-defaultsversion0.17.8References