CVE-2026-106489: Authorization Bypass via Path Traversal in Spotify Backstage TechDocs Backend
Vulnerability ID: CVE-2026-106489
CVSS Score: 6.5
Published: 2026-10-07
An authorization bypass vulnerability in the Spotify Backstage TechDocs backend plugin allows authenticated attackers with access to at least one valid TechDocs site to read arbitrary static documentation from other entities. This occurs due to un-sanitized relative subpaths passing directly to external storage drivers.
TL;DR
An authenticated user authorized to view at least one TechDocs site can craft a request with directory traversal sequences to bypass the Backstage permission framework and read private documentation from other entities.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22
- Attack Vector: Network
- CVSS v3.1 Score: 6.5
- EPSS Score: 0.00287
- Impact: High Confidentiality
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- Spotify Backstage
- @backstage/plugin-techdocs-backend
-
@backstage/plugin-techdocs-backend: < 2.2.4 (Fixed in:
2.2.4) -
backstage: < 1.54.6 (Fixed in:
1.54.6)
Code Analysis
Commit: bf6bbf7
Validate path containment in techdocs backend publisher routing
--- a/plugins/techdocs-backend/src/service/router.ts
+++
@@ -20,6 +20,11 @@
+const isPathWithinEntity = (requestPath: string): boolean => {
+ const relativePath = path.posix.normalize(
+ decodeURI(requestPath).replace(/^\/+/, ''),
+ );
+ return relativePath !== '..' && !relativePath.startsWith('../');
+};
Mitigation Strategies
- Upgrade the core backstage package and @backstage/plugin-techdocs-backend to patched versions.
- Deploy custom WAF rules to detect and reject URL-encoded path traversal sequences in TechDocs requests.
- Audit logs for request URLs targeting TechDocs containing double dot elements.
Remediation Steps:
- Identify all Backstage service instances in deployment environments.
- Execute the dependency upgrade using yarn: 'yarn workspace backend upgrade @backstage/plugin-techdocs-backend@^2.2.4'.
- Rebuild and redeploy the Backstage production container images.
- Validate the fix by attempting to request a traversal path and verifying a 404 response code is returned.
References
- Official NVD Record
- Official CVE Record
- GitHub Security Advisory
- Official Fix Commit
- Official Release / Version Tag
Read the full report for CVE-2026-106489 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)