PT-2026-3876 · Netflix · Backstage+1

Rugvip

·

Published

2026-01-21

·

Updated

2026-01-22

·

CVE-2026-24047

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Backstage versions prior to 0.1.17
Description The resolveSafeChildPath utility function in @backstage/backend-plugin-api did not properly validate symlink chains and dangling symlinks, leading to a path traversal issue. An attacker could bypass path validation by creating symlink chains or dangling symlinks that resolve outside the allowed directory. This function is used by Scaffolder actions and other backend components to control file operations within designated directories.
Recommendations Upgrade to version 0.1.17 or later. Run Backstage in a containerized environment with limited filesystem access. Restrict template creation to trusted users.

Exploit

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2026-24047
GHSA-2P49-45HJ-7MC9

Affected Products

@Backstage/Plugin-App-Backend
Backstage