GHSA-pgf8-28gg-vpr6 · Severity: medium · Ecosystem: npm — Path traversal
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could read sensitive files from the environment where TechDocs documentation is built and published by setting a particular path for `docs_dir` in `mkdocs.yml`. These files would then be available over the TechDocs backend API. This vulnerability is mitigated by the fact that an attacker would need access to modify the `mkdocs.yml` in the documentation source code, and would also need access to the TechDocs backend API. The vulnerability is patched in the `0.6.3` release of `@backstage/techdocs-common`.
Conclusion & alert: CVE-2021-32662 is rated Moderate Risk (49.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.28%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.48% | 1.28% | +0.80% |
| 2 | 2025-03-30 | 0.94% | 0.48% | -0.46% |
| 3 | 2025-03-29 | — | 0.94% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
GHSA-pgf8-28gg-vpr6 · Severity: medium · Ecosystem: npm — Path traversal
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linuxfoundation | backstage | < 0.6.3 | cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/backstage/backstage/commit/8cefadca04cbf01d0394b0cb1983247e5f1d6208 | Patch Third Party Advisory |
| https://github.com/backstage/backstage/releases/tag/release-2021-05-27 | Release Notes Third Party Advisory |
| https://github.com/backstage/backstage/security/advisories/GHSA-pgf8-28gg-vpr6 | Third Party Advisory |