`@backstage/backend-common` vulnerable to path traversal through symlinks
- Severity:
- High
Description
Paths checks with the resolveSafeChildPath utility were not exhaustive enough, leading to risk of path traversal vulnerabilities if symlinks can be injected by attackers.
Recommendation
Update the @backstage/backend-common package to the latest compatible version. Followings are version details:
Affected version(s): **>= 0.20.0, < 0.20.2 < 0.19.10 = 0.21.0** Patched version(s): **0.20.2 0.19.10 0.21.1**
References
Related Issues
- Agnai vulnerable to Relative Path Traversal in Image Upload - CVE-2024-47171
- Langchain Path Traversal vulnerability - CVE-2024-7774
- Nuxt Devtools has a Path Traversal: '../filedir - CVE-2024-23657
- Jan path traversal vulnerability - @janhq/core - CVE-2024-36858
You might also like:
- Tags:
- npm
- @backstage/backend-common
Anything's wrong? Let us know Last updated on March 24, 2026


