Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 8 min 133 bronnen 2 kritiek 46 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-106494

MEDIUM · 4.4 CVSS Gepubliceerd: CWE-22

Beschrijving

Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with protected files in the output directory. In certain deployment configurations, this could lead to content injection. This issue is fixed in version 0.17.8.

References