# CVE-2024-26150: Keeping Backstage safe and secure

DevFeed: [CVE-2024-26150: Keeping Backstage safe and secure](<https://devfeed.tech/articles/cve-2024-26150-keeping-backstage-safe-and-secure-12101.md>)

Original publisher: [Read original article](<https://backstage.io/blog/2024/02/28/security-notice>)

Author: Ben Lambert, Spotify & Sam Nixon, Roadie

Published: 2024-02-28T00:00:00Z

Content type: news

Language: en

Sources: [Backstage Software Catalog and Developer Platform Blog](<https://devfeed.tech/sources/backstage-software-catalog-and-developer-platform-blog.md>)

Topics: [Backstage](<https://devfeed.tech/topics/backstage.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Back end](<https://devfeed.tech/topics/backend.md>)

Tags: [backend](<https://devfeed.tech/tags/backend.md>), [backstage](<https://devfeed.tech/tags/backstage.md>), [cve](<https://devfeed.tech/tags/cve.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [developer-portal](<https://devfeed.tech/tags/developer-portal.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [idp](<https://devfeed.tech/tags/idp.md>), [internal-developer-platform](<https://devfeed.tech/tags/internal-developer-platform.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [software-catalog](<https://devfeed.tech/tags/software-catalog.md>), [software-templates](<https://devfeed.tech/tags/software-templates.md>), [techdocs](<https://devfeed.tech/tags/techdocs.md>), [update](<https://devfeed.tech/tags/update.md>), [v1](<https://devfeed.tech/tags/v1.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Backstage maintainers disclose CVE-2024-26150, a security vulnerability in the scaffolder's path traversal prevention utility. Fixes were released for versions newer than v1.15.0 and backported to older releases. Users should update to v1.23.2 or another fixed version.

## Source excerpt

TL;DR: For the Backstage maintainers, ensuring that the project is secure for every adopter and end user is one of our top priorities.