Loading HuntDB...

GHSA-3x3f-jcp3-g22j

GitHub Security Advisory

@backstage/plugin-catalog-backend Prototype Pollution vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact

A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API.

### Patches

This has been fixed in the `1.26.0` release of the `@backstage/plugin-catalog-backend` package.

### References

If you have any questions or comments about this advisory:

Open an issue in the [Backstage repository](https://github.com/backstage/backstage)
Visit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)

Affected Packages

npm @backstage/plugin-catalog-backend
Affected versions: 0 (fixed in 1.26.0)

Related CVEs

Key Information

GHSA ID
GHSA-3x3f-jcp3-g22j
Published
September 17, 2024 9:29 PM
Last Modified
November 18, 2024 4:27 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
@backstage/plugin-catalog-backend
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.