PT-2026-3876 · Netflix · Backstage+1
Rugvip
·
Published
2026-01-21
·
Updated
2026-01-22
·
CVE-2026-24047
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Backstage versions prior to 0.1.17
Description
The
resolveSafeChildPath utility function in @backstage/backend-plugin-api did not properly validate symlink chains and dangling symlinks, leading to a path traversal issue. An attacker could bypass path validation by creating symlink chains or dangling symlinks that resolve outside the allowed directory. This function is used by Scaffolder actions and other backend components to control file operations within designated directories.Recommendations
Upgrade to version 0.1.17 or later.
Run Backstage in a containerized environment with limited filesystem access.
Restrict template creation to trusted users.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Backstage/Plugin-App-Backend
Backstage