@backstage/plugin-scaffolder-backend
npm16 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @backstage/plugin-scaffolder-backendpage 1 of 1
- CVE-2021-41151MEDIUMCVSS 6.8EG 6.8fixed in 0.15.92021-10-18
Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitive files from the environment where Scaffolder Tasks are run. The attack is executed by crafting a custom Scaffolder tem…
- CVE-2021-43783HIGHCVSS 8.5EG 8.5fixed in 0.15.142021-11-29
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the template in a way that…
- CVE-2023-35926HIGHCVSS 8.0EG 8.0fixed in 1.15.02023-06-22
Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this sandbox so far has …
- CVE-2025-55285LOWCVSS 2.6EG 2.6fixed in 2.1.12025-08-15
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets w…
- CVE-2026-106461MEDIUMCVSS 4.3EG 4.3fixed in 4.1.02026-10-06
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An authenticated internal user may be able t…
- CVE-2026-106462MEDIUMCVSS 6.4EG 6.4fixed in 4.1.02026-10-06
Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall bac…
- CVE-2026-106499MEDIUMCVSS 4.9EG 4.9fixed in 4.1.02026-10-06
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.def…
- CVE-2026-106500HIGHCVSS 8.5EG 8.5fixed in 4.1.02026-10-06
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated u…
- CVE-2026-106501CRITICALCVSS 9.6EG 9.6fixed in 3.3.1, 3.4.1, 4.0.3 or 4.1.0, by version range2026-10-06
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage…
- CVE-2026-106502MEDIUMCVSS 5.3EG 5.3fixed in 4.1.02026-10-06
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure condi…
- CVE-2026-106503HIGHCVSS 8.1EG 8.1fixed in 3.3.1, 3.4.1, 4.0.3 or 4.1.0, by version range2026-10-06
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with…
- CVE-2026-106504MEDIUMCVSS 6.5EG 6.5fixed in 4.1.02026-10-06
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and…
- CVE-2026-106506MEDIUMCVSS 5.3EG 5.3fixed in 4.1.02026-10-06
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with…
- CVE-2026-24046HIGHCVSS 7.1EG 7.1fixed in 2.2.2, 3.0.2 or 3.1.1, by version range2026-01-21
Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder t…
- CVE-2026-29184MEDIUMCVSS 6.5EG 6.5fixed in 3.1.42026-03-07
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been p…
- CVE-2026-32237MEDIUMCVSS 6.5EG 6.5fixed in 3.1.52026-03-12
Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Se…
Check whether @backstage/plugin-scaffolder-backend is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @backstage/plugin-scaffolder-backend CVEs against the assets you own.
Book a Demo →