Plugin proxy backend: Backstage: Improper input validation in proxy-backend (CVE-2026-106491)
Description
An authenticated user of Backstage can exploit improper input validation in the proxy-backend plugin to cause the proxy to forward requests to paths outside the intended base path on configured target servers. This vulnerability requires authentication and affects versions of @backstage/plugin-proxy-backend prior to 0.6.17. A patch is available in version 0.6.17. As a workaround, deploying a reverse proxy or WAF to normalize request paths can mitigate the issue.
CVSS v3.1
Score 6.4medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-106491 describes an input validation flaw in the @backstage/plugin-proxy-backend component that allows an authenticated Backstage user to craft a request URL causing the proxy to forward the request outside the configured base path on the target server. This behavior is limited to servers already configured as proxy endpoints and requires user authentication. The vulnerability is addressed in version 0.6.17 of the plugin.
Potential Impact
An attacker with valid Backstage authentication can manipulate proxy requests to access unintended paths on target servers configured as proxy endpoints. This could lead to limited confidentiality and integrity impacts by accessing or influencing resources outside the intended proxy scope. There is no indication of availability impact or known exploitation in the wild.
Mitigation Recommendations
Upgrade @backstage/plugin-proxy-backend to version 0.6.17 or later to apply the official fix. Alternatively, deploy a reverse proxy or web application firewall (WAF) in front of Backstage to normalize request paths before they reach the backend, mitigating the risk of path traversal via crafted URLs.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9ghw-48h5-v2w5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-106491"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6ac6c0012cdf04f6568291b7
Added to database: 10/07/2026, 21:56:17 UTC
Last enriched: 10/07/2026, 22:14:59 UTC
Last updated: 10/07/2026, 22:14:59 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.