Executive brief
A security vulnerability exists in the Backstage authentication plugin, which is used to manage developer portal access. Under specific experimental configurations, an attacker could trick the server into making unauthorized requests to internal network locations. While the impact is limited because the attacker cannot see the response data, it could still be used to probe internal infrastructure or bypass certain network restrictions.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the `@backstage/plugin-auth-backend` package. The vulnerability occurs within the Client ID Metadata Document (CIMD) fetch mechanism. While the system validates the initial `client_id` hostname against private IP ranges, it fails to perform the same validation on subsequent HTTP redirects. An attacker can exploit this by providing a URL that redirects to an internal or restricted IP address. The impact is mitigated by the fact that the feature is experimental and disabled by default, and the attacker cannot read the response body or control request headers. The issue is fixed in version 0.27.1 by disabling redirect following during CIMD metadata fetches.
Affected products
- Backstage @backstage/plugin-auth-backend < 0.27.1
Timeline
- 2026-03-11: disclosed: Advisory published by maintainers
- 2026-03-12: advisory: GitHub Advisory published
- 2026-03-12: patched: Version 0.27.1 released