GHSA-3x3f-jcp3-g22j
GitHub Security Advisory
@backstage/plugin-catalog-backend Prototype Pollution vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
### Impact
A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API.
### Patches
This has been fixed in the `1.26.0` release of the `@backstage/plugin-catalog-backend` package.
### References
If you have any questions or comments about this advisory:
Open an issue in the [Backstage repository](https://github.com/backstage/backstage)
Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)
Affected Packages
npm
@backstage/plugin-catalog-backend
Affected versions:
0
(fixed in 1.26.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.