CVE Explorer
CVE-2026-29185
Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths. When these URLs were processed by integration functions that construct API URLs, the traversal segments could redirect requests to unintended SCM provider API endpoints using the configured server-side integration credentials. This issue has been patched in versi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"backstage","vendor":"backstage","versions":[{"status":"affected","version":"< 1.20.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3ab90243cb4d097fd83acd177407e365d74b9c64f80d156979ff94ca465f5b17 · sha256:ab831bd522906750… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3ab90243cb4d097fd83acd177407e365d74b9c64f80d156979ff94ca465f5b17 · sha256:ab831bd522906750… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3ab90243cb4d097fd83acd177407e365d74b9c64f80d156979ff94ca465f5b17 · sha256:ab831bd522906750… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/backstage/backstage/security/advisories/GHSA-95v5-prp4-5gv5","tags":["x_refsource_CONFIRM"],"url":"https://github.com/backstage/backstage/security/advisories/GHSA-95v5-prp4-5gv5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3ab90243cb4d097fd83acd177407e365d74b9c64f80d156979ff94ca465f5b17 · sha256:ab831bd522906750… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.