CVE-2026-29185 Details
Description
Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths. When these URLs were processed by integration functions that construct API URLs, the traversal segments could redirect requests to unintended SCM provider API endpoints using the configured server-side integration credentials. This issue has been patched in version 1.20.1.
A path traversal vulnerability has been identified in Backstage integrations prior to version 1.20.1. The issue arises from the SCM URL parsing, which allowed encoded path traversal sequences to be included in file paths. When these URLs were processed by integration functions that build API URLs, the traversal segments could redirect requests to unintended SCM provider API endpoints, using the integration credentials configured on the server side. This vulnerability affects instances utilizing any SCM integrations, such as GitHub, Bitbucket Server, or Bitbucket Cloud, particularly with the scaffolder or other features that allow user-provided SCM URLs.
Users should upgrade to Backstage version 1.20.1 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/backstage/backstage/security/advisories/GHSA-95v5-prp4-5gv5 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation backstage/integration | < 1.20.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 25, 2026 | Reanalysis | [email protected] |
| Apr 9, 2026 | Initial Analysis | [email protected] |
| Mar 7, 2026 | New CVE Received | [email protected] |