Ben Lambert
5 exploits
Active since Jan 2026
Backstage plugin-auth-backend < 0.27.1 - Server-Side Request Forgery via Client Metadata Redirect
CVSS 7.5
Backstage plugin-scaffolder-backend 3.1.0-3.1.4 - Authenticated Exposure of Sensitive Information via Dry-Run API
CVSS 4.4
Backstage Scaffolder - Symlink-Based Path Traversal and Arbitrary File Read/Write via Template Actions
CVSS 7.1
@backstage/cli-common < 0.1.17 - Path Traversal via Symlink Chain Bypass
CVSS 6.3
Backstage backend-defaults < 0.12.2 - Server-Side Request Forgery via FetchUrlReader Redirect Handling
CVSS 3.5