{"api_version":"1","generated_at":"2026-10-09T09:13:50+00:00","cve":"CVE-2026-106496","urls":{"html":"https://cve.report/CVE-2026-106496","api":"https://cve.report/api/cve/CVE-2026-106496.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-106496","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-106496"},"summary":{"title":"Backstage: Inconsistent enforcement of allowed location types during catalog processing","description":"Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-10-06 22:17:04","updated_at":"2026-10-07 17:16:49"},"problem_types":["CWE-22","CWE-863","CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","CWE-863 CWE-863: Incorrect Authorization"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"3.1","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"3.1","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-pcmq-25r3-5w9v","name":"https://github.com/backstage/backstage/security/advisories/GHSA-pcmq-25r3-5w9v","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/backstage/backstage/commit/23774b61560d851bc69cd6a77d12561b24d11afd","name":"https://github.com/backstage/backstage/commit/23774b61560d851bc69cd6a77d12561b24d11afd","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","name":"https://github.com/backstage/backstage/releases/tag/v1.54.6","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-106496","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106496","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"backstage","product":"backstage","version":"affected < 1.54.6","platforms":[]},{"source":"CNA","vendor":"@backstage","product":"plugin-catalog-backend","version":"affected < 3.9.1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"106496","cve":"CVE-2026-106496","epss":"0.002110000","percentile":"0.104380000","score_date":"2026-10-07","updated_at":"2026-10-08 00:05:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-106496","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-07T15:27:09.255888Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-07T17:06:48.520Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"backstage","vendor":"backstage","versions":[{"status":"affected","version":"< 1.54.6"}]},{"product":"plugin-catalog-backend","vendor":"@backstage","versions":[{"status":"affected","version":"< 3.9.1"}]}],"descriptions":[{"lang":"en","value":"Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-06T21:17:11.966Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/backstage/backstage/security/advisories/GHSA-pcmq-25r3-5w9v","tags":["x_refsource_CONFIRM"],"url":"https://github.com/backstage/backstage/security/advisories/GHSA-pcmq-25r3-5w9v"},{"name":"https://github.com/backstage/backstage/commit/23774b61560d851bc69cd6a77d12561b24d11afd","tags":["x_refsource_MISC"],"url":"https://github.com/backstage/backstage/commit/23774b61560d851bc69cd6a77d12561b24d11afd"},{"name":"https://github.com/backstage/backstage/releases/tag/v1.54.6","tags":["x_refsource_MISC"],"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6"}],"source":{"advisory":"GHSA-pcmq-25r3-5w9v","discovery":"UNKNOWN"},"title":"Backstage: Inconsistent enforcement of allowed location types during catalog processing"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-106496","datePublished":"2026-10-06T21:17:11.966Z","dateReserved":"2026-10-06T18:46:47.766Z","dateUpdated":"2026-10-07T17:06:48.520Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 22:17:04","lastModifiedDate":"2026-10-07 17:16:49","problem_types":["CWE-22","CWE-863","CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","CWE-863 CWE-863: Incorrect Authorization"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-07T15:27:09.255888Z","id":"CVE-2026-106496","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"106496","Ordinal":"1","Title":"Backstage: Inconsistent enforcement of allowed location types du","CVE":"CVE-2026-106496","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"106496","Ordinal":"1","NoteData":"Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.","Type":"Description","Title":"Backstage: Inconsistent enforcement of allowed location types du"}]}}}