Backstage: Improper input validation in proxy-backend
Description
Published by the National Vulnerability Database
Oct 6, 2026
Published to the GitHub Advisory Database
Oct 7, 2026
Reviewed
Oct 7, 2026
Impact
An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the configured base path on the target server. This is limited to target servers already configured as proxy endpoints and requires Backstage authentication by default.
Patches
Patched in
@backstage/plugin-proxy-backendversion0.6.17Workarounds
References