Description
A malicious actor with the ability to register entities in the Software Catalog is able to write files to arbitrary paths on the techdocs backend host instance when techdocs.publisher.type is set to local.
Recommendation
Update the @backstage/techdocs-common package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.11.16
- Patched version(s): 0.11.16
References
Related Issues
- obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr - Vulnerability
- jsPDF has Local File Inclusion/Path Traversal vulnerability - CVE-2025-68428
- Path traversal - CVE-2021-32662
- Jan path traversal vulnerability - @janhq/core - CVE-2024-36858
You might also like:
- Tags:
- npm
- @backstage/techdocs-common
Anything's wrong? Let us know Last updated on January 12, 2023


