Junglewise Threat Intelligence

CVE-2026-29185: Backstage path traversal in SCM URL parsing

CVE-2026-29185 · Severity: low · CVSS 3.1 · Published 2026-03-05

Vendors: Backstage, npm.

Executive brief

Backstage is an open-source developer portal framework that integrates with source control systems like GitHub and Bitbucket. A vulnerability in its SCM integration allows an attacker with elevated privileges to craft malicious URLs that bypass path validation, potentially redirecting API requests to unintended endpoints and exposing sensitive SCM credentials configured in the system.

Technical details

A path traversal vulnerability (CWE-22) exists in the SCM URL parsing logic used by Backstage integrations. Encoded path traversal sequences (e.g., encoded ../ characters) in user-provided SCM URLs were not properly validated before being used to construct API URLs. When processed by integration functions, these traversal segments could redirect requests to unintended SCM provider API endpoints, allowing attackers to abuse configured server-side integration credentials. The vulnerability requires high privileges (authenticated admin/developer access) and affects instances using GitHub, Bitbucket Server, or Bitbucket Cloud integrations with the scaffolder or other SCM URL-accepting features. Patch version 1.20.1 of @backstage/integration fixes this issue; all versions ≤1.20.0 are vulnerable.

Affected products

  • Backstage @backstage/integration <=1.20.0

Timeline

  • 2026-03-05: disclosed
  • 2026-03-05: patched: Fixed in @backstage/integration version 1.20.1

References