CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-106489

CVE-2026-106489: Authorization Bypass via Path Traversal in Spotify Backstage TechDocs Backend

Alon Barad
Alon Barad
Software Engineer

Oct 7, 2026·7 min read·3 visits

Executive Summary (TL;DR)

An authenticated user authorized to view at least one TechDocs site can craft a request with directory traversal sequences to bypass the Backstage permission framework and read private documentation from other entities.

An authorization bypass vulnerability in the Spotify Backstage TechDocs backend plugin allows authenticated attackers with access to at least one valid TechDocs site to read arbitrary static documentation from other entities. This occurs due to un-sanitized relative subpaths passing directly to external storage drivers.

Vulnerability Overview

Spotify Backstage is an open-source framework used to build centralized developer portals. The TechDocs plugin (@backstage/plugin-techdocs-backend) is responsible for serving technical documentation directly within the Backstage portal. In standard deployment scenarios, documentation is written in Markdown, generated as static assets (HTML, CSS, and images) using tools like MkDocs, and then hosted on external storage systems like Amazon S3, Google Cloud Storage, or Azure Blob Storage.

When the Backstage permission framework is enabled, access to specific entity documentation is regulated through access control policies. When an authenticated developer attempts to view a document, the application performs permission checks using the catalog entity details (namespace, kind, and name). This design prevents unauthorized developers from accessing proprietary designs, infrastructure schemas, or internal API structures.

A vulnerability in the routing component of @backstage/plugin-techdocs-backend breaks this isolation model. When configured with an external TechDocs builder and an external storage provider, the application fails to validate directory containment of requested subpaths. This exposes an attack surface where low-privileged authenticated users can view restricted files from unrelated entities, provided they have access to at least one valid TechDocs repository.

Root Cause Analysis

The core flaw resides in how Backstage routes requests for static TechDocs files. The backend application implements an Express route handler to serve these assets under /static/docs/:namespace/:kind/:name.

During request processing, the Backstage permission middleware extracts the parsed parameter values (such as namespace, kind, and name) to execute access authorization lookups. If the user is authorized to read the specified entity, the request is passed to the underlying storage publisher. However, the application uses the raw request path (req.path), which contains the subpath of the requested file, without sanitizing it for path traversal vectors.

An attacker can supply URL-encoded traversal sequences like %2e%2e within the subpath portion of the request. Since the route parameters still map to a valid, permitted entity, the authorization check succeeds. The downstream storage client receives the un-sanitized path containing traversal sequences, which are decoded and normalized during interaction with the external storage provider (e.g., S3 or GCS). This shifts the target file lookup outside of the authorized entity's directory into an unauthorized peer directory.

Code Analysis and Fix Assessment

The official fix, introduced in commit bf6bbf7326ada7d96d7b2c4ebc4a71546106f311, addresses the root cause by validating the containment of requested subpaths before checking permissions or fetching files. It introduces the helper function isPathWithinEntity to check that the path does not escape the parent entity context.

Below is the security validation logic added in router.ts:

import path from 'node:path';
 
// Helper to evaluate if the request path stays within the entity boundary
const isPathWithinEntity = (requestPath: string): boolean => {
  // Decode URL encoding first to catch encoded patterns like %2e%2e
  const relativePath = path.posix.normalize(
    decodeURI(requestPath).replace(/^\/+/, ''),
  );
  // Ensure the path does not resolve to a parent directory
  return relativePath !== '..' && !relativePath.startsWith('../');
};

This verification functions as follows:

  1. decodeURI: Decodes URL-encoded sequences like %2e to . and %2f to /. This ensures the validation detects hidden traversal characters.
  2. path.posix.normalize: Resolves relative sequences such as . and ... For example, entity-a/../entity-b resolves to entity-b, which would then fail the containment check if normalized from the root.
  3. Containment Check: Verifies that the normalized relative path does not equal .. and does not start with ../.

While this fix successfully mitigates standard traversal attacks, several implementation considerations exist:

  • Operating System Separators: The function relies on path.posix.normalize. On Windows-based systems where Backstage is run locally with the local file publisher, native Windows path separators (\) are resolved by the OS. Since POSIX normalization does not handle backslashes, a path utilizing Windows separators (e.g., ..%5c..%5c) might bypass POSIX normalization but still cause traversal when accessed via the local Windows filesystem.
  • Double Decoding: The path is decoded exactly once inside isPathWithinEntity using decodeURI. If there is an upstream proxy (e.g., NGINX, Cloudflare, or AWS Application Load Balancer) that normalizes double URL-encoded sequences, or if downstream drivers perform extra decodes, double-encoded traversal sequences (%252e%252e) might bypass this single-stage filter.

Exploitation Methodology

To execute this attack, an attacker must satisfy several prerequisites. First, they must possess valid credentials to authenticate to the Backstage developer portal. Second, the Backstage portal must have the permission framework enabled, utilize an external TechDocs builder, and fetch documentation from an external storage provider. Finally, the attacker must have read permissions for at least one catalog entity that hosts TechDocs.

In a typical scenario, the attacker identifies a permitted entity (entity-a) and a target restricted entity (entity-b). The attacker then constructs a GET request targeting the /api/techdocs/static/docs/ routing endpoint. By appending a URL-encoded traversal string (%2e%2e/entity-b/index.html) to the authorized endpoint, the attacker initiates the exploit.

An example HTTP request demonstrating this bypass:

GET /api/techdocs/static/docs/default/component/entity-a/%2e%2e/entity-b/index.html HTTP/1.1
Host: backstage.internal.net
Authorization: Bearer <valid_low_privilege_token>
User-Agent: Mozilla/5.0
Accept: text/html,application/xhtml+xml

When this request is processed:

  • The Express router matches the route parameter :name to entity-a.
  • The permission framework validates the token and checks if the user has access to default/component/entity-a.
  • Because the user is authorized for entity-a, the system permits the request.
  • The backend fetches the raw request path from the storage provider, which normalizes the directory reference to retrieve files from default/component/entity-b/index.html, returning unauthorized internal information to the attacker.

Impact Assessment

The impact of this vulnerability is classified as Medium, with a CVSS 3.1 score of 6.5. This classification represents high confidentiality impact but zero direct impact on integrity or availability. The vulnerability does not allow write access, meaning attackers cannot alter documentation files, upload malicious assets, or achieve remote code execution on the underlying server.

Despite the Medium severity rating, the confidentiality risks inside corporate developer portals are significant. Technical documentation within developer portals frequently contains sensitive system architecture diagrams, internal endpoint definitions, database models, internal service dependencies, and potentially hardcoded non-production credentials or API keys.

Exposing internal system maps and service dependencies provides high-value intelligence to malicious actors. An attacker can use this information to map the internal attack surface of an organization, identifying high-value targets, security weaknesses, and authentication boundaries for secondary exploits.

Remediation and Detection Guidance

The recommended path of remediation is upgrading the affected packages to their patched versions. Specifically, @backstage/plugin-techdocs-backend must be updated to version 2.2.4 or higher, and the core backstage framework must be updated to version 1.54.6 or higher.

To update these packages in your workspace, run the following commands:

# Upgrade the plugin in your backend workspace
yarn workspace backend upgrade @backstage/plugin-techdocs-backend@^2.2.4
 
# Alternatively, execute the core CLI upgrade process
yarn backstage-cli versions:bump

In situations where upgrading cannot be executed immediately, administrators should implement temporary network-level and application-level mitigations. Web Application Firewalls (WAFs) should be configured with custom rules to inspect inbound URL paths targeting the /api/techdocs/static/docs/ endpoint. Any request containing encoded traversal sequences (%2e%2e, %2f, %5c, or native ..) should be blocked immediately.

Official Patches

SpotifyOfficial fix introducing isPathWithinEntity validation

Fix Analysis (1)

Technical Appendix

CVSS Score
6.5/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Probability
0.29%
Top 81% most exploited
1,500
via Shodan

Affected Systems

Spotify Backstage@backstage/plugin-techdocs-backend

Affected Versions Detail

Product
Affected Versions
Fixed Version
@backstage/plugin-techdocs-backend
Spotify
< 2.2.42.2.4
backstage
Spotify
< 1.54.61.54.6
AttributeDetail
CWE IDCWE-22
Attack VectorNetwork
CVSS v3.1 Score6.5
EPSS Score0.00287
ImpactHigh Confidentiality
Exploit Statuspoc
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Vulnerability Timeline

Security patch authored and signed off under commit bf6bbf7326ada7d96d7b2c4ebc4a71546106f311.
2026-08-24
Public disclosure of GHSA-rg9r-hr7g-5gc2 and release of backstage version 1.54.6.
2026-10-06
CVE-2026-106489 officially published in the global CVE database.
2026-10-06
National Vulnerability Database (NVD) completes analysis and registers CVSS score.
2026-10-07

References & Sources

  • [1]Official NVD Record
  • [2]Official CVE Record
  • [3]GitHub Security Advisory
  • [4]Official Fix Commit
  • [5]Official Release / Version Tag

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•12 minutes ago•CVE-2026-106443
8.8

CVE-2026-106443: Remote Code Execution in WeasyPrint via Unvalidated Pillow EPS Processing

A critical remote code execution vulnerability was identified in WeasyPrint prior to version 70.0. When compiling HTML containing a malicious Encapsulated PostScript (EPS) graphic on a host with Ghostscript installed, Pillow invokes Ghostscript to process the image, executing arbitrary PostScript commands.

Amit Schendel
Amit Schendel
1 views•8 min read
•about 2 hours ago•CVE-2026-106502
5.3

CVE-2026-106502: Sensitive Information Exposure in Backstage Scaffolder Backend

The @backstage/plugin-scaffolder-backend package prior to version 4.1.0 is vulnerable to sensitive information exposure in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user can retrieve backend-managed credentials, such as VCS access tokens and API keys, from affected task execution events and stored database logs. This vulnerability has been remediated in version 4.1.0 of the package and is bundled with the Backstage platform release v1.54.6.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 3 hours ago•CVE-2026-61436
8.6

CVE-2026-61436: Missing Webhook Signature Verification in PraisonAI AgentMail Endpoint

A critical security flaw exists in PraisonAI before version 4.6.78 when operating in AgentMail webhook mode. The application processes incoming POST requests without checking for cryptographic signatures, allowing unauthenticated attackers to forge emails, spoof identities, and force AI agents to execute unauthorized operations.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 4 hours ago•CVE-2026-62179
6.5

CVE-2026-62179: Missing Authorization in praisonai-platform Dependency Deletion Route

A missing authorization vulnerability (CWE-862) exists in praisonai-platform versions prior to 0.1.9, allowing low-privileged workspace members to delete planning dependencies on issues owned by administrators by routing the deletion request through an attacker-owned issue.

Amit Schendel
Amit Schendel
3 views•6 min read
•about 5 hours ago•CVE-2026-46438
6.5

CVE-2026-46438: Broken Object Level Authorization in wger Workout Log Endpoint

CVE-2026-46438 is a critical Broken Object Level Authorization (BOLA) / Insecure Direct Object Reference (IDOR) vulnerability identified in the wger fitness manager prior to version 2.6. An authenticated attacker can exploit a missing authorization check on the slot_entry API parameter to inject unauthorized workout logs into another user's training schedule. This results in the corruption of the target user's automated progressive-overload calculations.

Amit Schendel
Amit Schendel
7 views•5 min read
•about 11 hours ago•CVE-2026-105795
3.1

CVE-2026-105795: Unvalidated Custom Extension Path Traversal in Microsoft Kiota

CVE-2026-105795 (GHSA-6gw6-rv2g-25mg) is a critical path traversal vulnerability in Microsoft Kiota, an OpenAPI-based HTTP client and plugin manifest generator. In affected versions (1.25.1 to < 1.35.0), Kiota propagates the unvalidated `x-ai-capabilities.response_semantics.oauth_card_path` vendor extension directly into generated API plugin manifests, leading to potential path traversal exploitation by downstream consumers.

Alon Barad
Alon Barad
2 views•6 min read