Backend defaults used by Backstage backend apps
89%
Total Score
100
95
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-24048 @backstage/backend-defaults is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 0.12.2, 0.13.0 - 0.13.2 and 0.14.0 - 0.14.1. | 0.0.0 - 0.12.20.13.0 - 0.13.20.14.0 - 0.14.1 | Low |
CVE-2026-24046 @backstage/backend-defaults is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 0.12.2, 0.13.0 - 0.13.2 and 0.14.0 - 0.14.1. | 0.0.0 - 0.12.20.13.0 - 0.13.20.14.0 - 0.14.1 | High |
AIKIDO-2024-10342 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @backstage/backend-defaults is vulnerable to Accidental exposure of sensitive info possible in versions 0.1.0 - 0.5.0. | 0.1.0 - 0.5.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
pg Version ^8.11.3 | — | — |
yn Version ^4.0.0 | — | — |
tar Version ^7.5.6 | — | — |
zod Version ^3.25.76 || ^4.0.0 | — | — |
cors Version ^2.8.5 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant