CVE Tools

Backstage

29 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Backstage, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.

Backstage CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Backstage CVEs per month
MonthCVEs
2024-101
2024-111
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-081
2025-090
2025-100
2025-110
2025-120
2026-015
2026-020
2026-035
2026-040
2026-050
2026-060
2026-070
2026-081
2026-091

Severity

How the 29 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High931%
  • Medium1655%
  • Low414%

Latest CVEs

The 15 most recently published vulnerabilities affecting Backstage.

  1. CVE-2026-88064Backstage: Improper input validation in TechDocs MkDocs configuration8.8
  2. CVE-2026-73563Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend`4.7
  3. CVE-2026-32236@backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch7.5
  4. CVE-2026-32235@backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass5.9
  5. CVE-2026-29186@backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution7.7
  6. CVE-2026-29184@backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction Bypass2.0
  7. CVE-2026-29185@backstage/integration: Potential reading of SCM URLs using built in token2.7
  8. CVE-2026-25152@backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator5.3
  9. CVE-2026-25153@backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks7.7
  10. CVE-2026-24048Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`3.5
  11. CVE-2026-24047@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass6.3
  12. CVE-2026-24046Backstage has a Possible Symlink Path Traversal in Scaffolder Actions7.1
  13. CVE-2025-55285@backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`2.6
  14. CVE-2025-32791Permission policy information leakage in Backstage permission system4.3
  15. CVE-2024-53983Server-side request forgery in Backstage Scaffolder plugin5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store