The Backstage backend plugin that provides the Backstage catalog
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2024-45815 @backstage/plugin-catalog-backend is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 1.26.0. | 0.0.0 - 1.26.0 | Medium |
AIKIDO-2024-10134 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @backstage/plugin-catalog-backend is vulnerable to Information Disclosure in versions 0.1.1 - 1.22.0. | 0.1.1 - 1.22.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
yn Version ^4.0.0 | — | — |
ajv Version ^8.10.0 | — | — |
zod Version ^3.25.76 || ^4.0.0 | — | — |
glob Version ^13.0.0 | — | — |
knex Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant