Vulnerabilities/

Backstage vulnerable to potential reading of SCM URLs using built in token

Severity:
Low

Description

A vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths.

Recommendation

Update the @backstage/integration package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@backstage/integration
Anything's wrong? Let us know Last updated on March 09, 2026