fix(deps): update dependency @backstage/backend-defaults ( 0.13.1 ➔ 0.13.2 ) [security] #82

Open
renovate wants to merge 1 commit from renovate/npm-backstage-backend-defaults-vulnerability into main
Member

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@backstage/backend-defaults (source) 0.13.1 → 0.13.2 age adoption passing confidence

🔒 Security update: prioritize review and verify the vulnerable component is actually deployed.

Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.

Released is the upstream publish time. — means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so minimumReleaseAge cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's minimumReleaseAge to Released to get the eligibility moment.


Backstage has a Possible SSRF when reading from allowed URL's in backend.reading.allow

CVE-2026-24048 / GHSA-q2x5-4xjx-c6p9

More information

Details

Impact

The FetchUrlReader component, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. This allowed an attacker who controls a host listed in backend.reading.allow to redirect requests to internal or sensitive URLs that are not on the allowlist, bypassing the URL allowlist security control.

This is a Server-Side Request Forgery (SSRF) vulnerability that could allow access to internal resources, but it does not allow attackers to include additional request headers.

Patches

This vulnerability is fixed in @backstage/backend-defaults version 0.12.2, 0.13.2, 0.14.1, and 0.15.0. Users should upgrade to this version or later.

Workarounds
  • Restrict backend.reading.allow to only trusted hosts that you control and that do not issue redirects
  • Ensure allowed hosts do not have open redirect vulnerabilities
  • Use network-level controls to block access from Backstage to sensitive internal endpoints
References

Severity

  • CVSS Score: 3.5 / 10 (Low)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


CVE-2026-24046 / GHSA-rq6q-wr2q-7pgp

More information

Details

Impact

Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:

  1. Read arbitrary files via the debug:log action by creating a symlink pointing to sensitive files (e.g., /etc/passwd, configuration files, secrets)
  2. Delete arbitrary files via the fs:delete action by creating symlinks pointing outside the workspace
  3. Write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks

This affects any Backstage deployment where users can create or execute Scaffolder templates.

Patches

This vulnerability is fixed in the following package versions:

  • @backstage/backend-defaults version 0.12.2, 0.13.2, 0.14.1, 0.15.0
  • @backstage/plugin-scaffolder-backend version 2.2.2, 3.0.2, 3.1.1
  • @backstage/plugin-scaffolder-node version 0.11.2, 0.12.3

Users should upgrade to these versions or later.

Workarounds
  • Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates
  • Restrict who can create and execute Scaffolder templates using the permissions framework
  • Audit existing templates for symlink usage
  • Run Backstage in a containerized environment with limited filesystem access
References

Severity

  • CVSS Score: 7.1 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

backstage/backstage (@​backstage/backend-defaults)

v0.13.2

Compare Source


Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [@backstage/backend-defaults](https://backstage.io) ([source](https://github.com/backstage/backstage/tree/HEAD/packages/backend-defaults)) | [`0.13.1` → `0.13.2`](https://renovatebot.com/diffs/npm/@backstage%2fbackend-defaults/0.13.1/0.13.2) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@backstage%2fbackend-defaults/0.13.2?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@backstage%2fbackend-defaults/0.13.2?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@backstage%2fbackend-defaults/0.13.1/0.13.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@backstage%2fbackend-defaults/0.13.1/0.13.2?slim=true) | 🔒 **Security update**: prioritize review and verify the vulnerable component is actually deployed. Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge. `Released` is the upstream publish time. `—` means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so `minimumReleaseAge` cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's `minimumReleaseAge` to `Released` to get the eligibility moment. --- ### Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow` [CVE-2026-24048](https://nvd.nist.gov/vuln/detail/CVE-2026-24048) / [GHSA-q2x5-4xjx-c6p9](https://github.com/advisories/GHSA-q2x5-4xjx-c6p9) <details> <summary>More information</summary> #### Details ##### Impact The `FetchUrlReader` component, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. This allowed an attacker who controls a host listed in `backend.reading.allow` to redirect requests to internal or sensitive URLs that are not on the allowlist, bypassing the URL allowlist security control. This is a Server-Side Request Forgery (SSRF) vulnerability that could allow access to internal resources, but it does not allow attackers to include additional request headers. ##### Patches This vulnerability is fixed in `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, and 0.15.0. Users should upgrade to this version or later. ##### Workarounds - Restrict `backend.reading.allow` to only trusted hosts that you control and that do not issue redirects - Ensure allowed hosts do not have open redirect vulnerabilities - Use network-level controls to block access from Backstage to sensitive internal endpoints ##### References - [OWASP SSRF Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html) #### Severity - CVSS Score: 3.5 / 10 (Low) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-q2x5-4xjx-c6p9](https://github.com/backstage/backstage/security/advisories/GHSA-q2x5-4xjx-c6p9) - [https://nvd.nist.gov/vuln/detail/CVE-2026-24048](https://nvd.nist.gov/vuln/detail/CVE-2026-24048) - [https://github.com/backstage/backstage/commit/27f9061d24affd1b9212fe0abd476bfc3fbaedcb](https://github.com/backstage/backstage/commit/27f9061d24affd1b9212fe0abd476bfc3fbaedcb) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-q2x5-4xjx-c6p9) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Backstage has a Possible Symlink Path Traversal in Scaffolder Actions [CVE-2026-24046](https://nvd.nist.gov/vuln/detail/CVE-2026-24046) / [GHSA-rq6q-wr2q-7pgp](https://github.com/advisories/GHSA-rq6q-wr2q-7pgp) <details> <summary>More information</summary> #### Details ##### Impact Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to: 1. **Read arbitrary files** via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets) 2. **Delete arbitrary files** via the `fs:delete` action by creating symlinks pointing outside the workspace 3. **Write files outside the workspace** via archive extraction (tar/zip) containing malicious symlinks This affects any Backstage deployment where users can create or execute Scaffolder templates. ##### Patches This vulnerability is fixed in the following package versions: - `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, 0.15.0 - `@backstage/plugin-scaffolder-backend` version 2.2.2, 3.0.2, 3.1.1 - `@backstage/plugin-scaffolder-node` version 0.11.2, 0.12.3 Users should upgrade to these versions or later. ##### Workarounds - Follow the recommendation in the [Backstage Threat Model](https://backstage.io/docs/overview/threat-model#scaffolder) to limit access to creating and updating templates - Restrict who can create and execute Scaffolder templates using the permissions framework - Audit existing templates for symlink usage - Run Backstage in a containerized environment with limited filesystem access ##### References - [CWE-59: Improper Link Resolution Before File Access](https://cwe.mitre.org/data/definitions/59.html) - [OWASP Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal) #### Severity - CVSS Score: 7.1 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-rq6q-wr2q-7pgp](https://github.com/backstage/backstage/security/advisories/GHSA-rq6q-wr2q-7pgp) - [https://nvd.nist.gov/vuln/detail/CVE-2026-24046](https://nvd.nist.gov/vuln/detail/CVE-2026-24046) - [https://github.com/backstage/backstage/commit/c641c147ab371a9a8a2f5f67fdb7cb9c97ef345d](https://github.com/backstage/backstage/commit/c641c147ab371a9a8a2f5f67fdb7cb9c97ef345d) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-rq6q-wr2q-7pgp) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>backstage/backstage (@&#8203;backstage/backend-defaults)</summary> ### [`v0.13.2`](https://github.com/backstage/backstage/compare/v0.13.1...3a50585da82823ade977eb94a5ff2c799b24239e) [Compare Source](https://github.com/backstage/backstage/compare/v0.13.1...3a50585da82823ade977eb94a5ff2c799b24239e) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjI3MS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSIsInNlY3VyaXR5IiwidHlwZS9wYXRjaCJdfQ==-->
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/npm-backstage-backend-defaults-vulnerability:renovate/npm-backstage-backend-defaults-vulnerability
git switch renovate/npm-backstage-backend-defaults-vulnerability

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/npm-backstage-backend-defaults-vulnerability
git switch renovate/npm-backstage-backend-defaults-vulnerability
git rebase main
git switch main
git merge --ff-only renovate/npm-backstage-backend-defaults-vulnerability
git switch renovate/npm-backstage-backend-defaults-vulnerability
git rebase main
git switch main
git merge --no-ff renovate/npm-backstage-backend-defaults-vulnerability
git switch main
git merge --squash renovate/npm-backstage-backend-defaults-vulnerability
git switch main
git merge --ff-only renovate/npm-backstage-backend-defaults-vulnerability
git switch main
git merge renovate/npm-backstage-backend-defaults-vulnerability
git push origin main
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/backstage-application!82
No description provided.