DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-106489: CVE-2026-106489: Authorization Bypass via Path Traversal in Spotify Backstage TechDocs Backend

CVE-2026-106489: Authorization Bypass via Path Traversal in Spotify Backstage TechDocs Backend

Vulnerability ID: CVE-2026-106489
CVSS Score: 6.5
Published: 2026-10-07

An authorization bypass vulnerability in the Spotify Backstage TechDocs backend plugin allows authenticated attackers with access to at least one valid TechDocs site to read arbitrary static documentation from other entities. This occurs due to un-sanitized relative subpaths passing directly to external storage drivers.

TL;DR

An authenticated user authorized to view at least one TechDocs site can craft a request with directory traversal sequences to bypass the Backstage permission framework and read private documentation from other entities.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-22
  • Attack Vector: Network
  • CVSS v3.1 Score: 6.5
  • EPSS Score: 0.00287
  • Impact: High Confidentiality
  • Exploit Status: poc
  • KEV Status: Not Listed

Affected Systems

  • Spotify Backstage
  • @backstage/plugin-techdocs-backend
  • @backstage/plugin-techdocs-backend: < 2.2.4 (Fixed in: 2.2.4)
  • backstage: < 1.54.6 (Fixed in: 1.54.6)

Code Analysis

Commit: bf6bbf7

Validate path containment in techdocs backend publisher routing

--- a/plugins/techdocs-backend/src/service/router.ts
+++
@@ -20,6 +20,11 @@
+const isPathWithinEntity = (requestPath: string): boolean => {
+  const relativePath = path.posix.normalize(
+    decodeURI(requestPath).replace(/^\/+/, ''),
+  );
+  return relativePath !== '..' && !relativePath.startsWith('../');
+};
Enter fullscreen mode Exit fullscreen mode

Mitigation Strategies

  • Upgrade the core backstage package and @backstage/plugin-techdocs-backend to patched versions.
  • Deploy custom WAF rules to detect and reject URL-encoded path traversal sequences in TechDocs requests.
  • Audit logs for request URLs targeting TechDocs containing double dot elements.

Remediation Steps:

  1. Identify all Backstage service instances in deployment environments.
  2. Execute the dependency upgrade using yarn: 'yarn workspace backend upgrade @backstage/plugin-techdocs-backend@^2.2.4'.
  3. Rebuild and redeploy the Backstage production container images.
  4. Validate the fix by attempting to request a traversal path and verifying a 404 response code is returned.

References


Read the full report for CVE-2026-106489 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)