Advisories for Npm/@Backstage/Plugin-Catalog-Unprocessed-Entities package

2026

Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

The unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module.