Backstage OIDC Provider Redirect URI Allowlist Bypass Vulnerability

Vulnerability

A redirect URI allowlist bypass vulnerability has been identified in the experimental OpenID Connect (OIDC) provider of Backstage's authentication backend plugin, specifically in versions prior to 0.27.1. This vulnerability affects instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents, and have configured allowedRedirectUriPatterns. An attacker can exploit this by crafting a redirect URI that bypasses the allowlist validation and directs to an attacker-controlled host. If a victim consents to the OAuth request, their authorization code is sent to the attacker, who can then exchange it for a valid access token. This exploitation requires victim interaction and the explicit activation of certain experimental features, which are not enabled by default.

Impact

Exploitation of this vulnerability allows for a redirect URI allowlist bypass, enabling an attacker to intercept authorization codes and exchange them for access tokens, potentially leading to unauthorized access.

Remediation

Users can upgrade to Backstage version 0.27.1 or later to address this vulnerability. If the experimental Dynamic Client Registration and Client ID Metadata Documents features are not needed, they should be disabled.

Added: Mar 12, 2026, 7:23 PM
Updated: Mar 12, 2026, 7:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.2
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.