Description
A malicious actor with the ability to register entities in the Software Catalog is able to write files to arbitrary paths on the techdocs backend host instance when techdocs.publisher.type is set to local.
Recommendation
Update the @backstage/techdocs-common package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.11.16
- Patched version(s): 0.11.16
References
Could your website be exposed too?
SmartScanner can check your website for Path traversal for local publishers in TechDocs backend and gives you actionable findings to investigate.
Start a free scanRelated Issues
- obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr - Vulnerability
- jsPDF has Local File Inclusion/Path Traversal vulnerability - CVE-2025-68428
- Path traversal - CVE-2021-32662
- Jan path traversal vulnerability - @janhq/core - CVE-2024-36858


