📦 Backstage

by Linuxfoundation

🔍 What is Backstage?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25153

HIGH CVSS 7.7 Jan 30, 2026

This vulnerability allows attackers to execute arbitrary Python code on TechDocs build servers when configured with 'runIn: local'. Malicious actors who can modify a repository's mkdocs.yml file can e...

CVE-2026-25152

MEDIUM CVSS 5.3 Jan 30, 2026

A path traversal vulnerability in Backstage's TechDocs local generator allows attackers to read arbitrary files from the host filesystem when processing documentation from untrusted sources. This affe...

CVE-2024-45816

MEDIUM CVSS 6.5 Sep 17, 2024

This vulnerability in Backstage's TechDocs plugin allows attackers to access the entire AWS S3 or GCS storage bucket contents when using those providers, bypassing intended permission checks. This aff...