GHSA-29gx-h2m3-xw44MediumCVSS 6.4
Backstage's scaffolder credential handling may allow unintended GitHub authentication fallback
🔗 CVE IDs covered (1)
📋 Description
Impact
Scaffolder actions that interact with source control systems may not consistently enforce the intended credential boundaries under certain configurations. An authenticated user could perform operations with broader access than intended.
Patches
@backstage/plugin-scaffolder-backendversion4.1.0@backstage/plugin-scaffolder-backend-module-azureversion0.2.25@backstage/plugin-scaffolder-backend-module-bitbucket-cloudversion0.3.10@backstage/plugin-scaffolder-backend-module-bitbucket-serverversion0.2.25@backstage/plugin-scaffolder-backend-module-githubversion0.9.13@backstage/plugin-scaffolder-backend-module-gitlabversion0.11.10
The fix introduces a new configuration option that enforces user-provided credentials for supported SCM actions. The new behavior is opt-in for compatibility. After upgrading, set:
scaffolder:
requireScmUserCredentials: true
Before enabling this setting, review and update your templates as described in the software templates documentation referred to below.
Workarounds
If you cannot upgrade and enable the setting immediately:
- Restrict who can create Scaffolder tasks and which templates they can execute.
- Limit SCM integration credentials to the minimum repository read and mutation permissions required.
- Remove integration credentials for SCM hosts where all required operations can use explicitly supplied user tokens.
🎯 Affected products6
- npm/@backstage/plugin-scaffolder-backend:< 4.1.0
- npm/@backstage/plugin-scaffolder-backend-module-github:< 0.9.13
- npm/@backstage/plugin-scaffolder-backend-module-gitlab:< 0.11.10
- npm/@backstage/plugin-scaffolder-backend-module-azure:< 0.2.25
- npm/@backstage/plugin-scaffolder-backend-module-bitbucket-cloud:< 0.3.10
- npm/@backstage/plugin-scaffolder-backend-module-bitbucket-server:< 0.2.25
🔗 References (6)
- https://github.com/backstage/backstage/security/advisories/GHSA-29gx-h2m3-xw44
- https://nvd.nist.gov/vuln/detail/CVE-2026-106462
- https://github.com/backstage/backstage/commit/6fb2a41ea47da37eafe5ea744050
- https://github.com/backstage/backstage/commit/6fb2a41ea47da37eafe5ea744050ef90be6820c0
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-29gx-h2m3-xw44