Description
A vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths.
Recommendation
Update the @backstage/integration package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.20.0
- Patched version(s): 1.20.1
References
Could your website be exposed too?
SmartScanner can check your website for Backstage vulnerable to potential reading of SCM URLs using built in token and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cinny vulnerable to access token disclosure via invalidated emoji pack avatar URL in service worker - CVE-2026-42553
- Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS - CVE-2026-40171
- Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer - CVE-2026-41680
- @siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes - CVE-2026-31861
You might also like:
See something that needs correcting? Let us knowUpdated March 09, 2026


