CVE-2024-46976

MEDIUM

Backstage < 1.10.13 - Stored Cross-Site Scripting in TechDocs Content

Title source: llm
STIX 2.1

Description

Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject executable scripts in the TechDocs content that will be executed in the victim's browser when browsing documentation or navigating to an attacker provided link. This has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package. users are advised to upgrade. There are no known workarounds for this vulnerability.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0026
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-693
Status published
Products (2)
backstage/plugin-techdocs-backend 0 - 1.10.13npm
linuxfoundation/backstage < 1.10.13
Published Sep 17, 2024
Tracked Since Feb 18, 2026