GHSA-75qf-886x-5xf2MediumCVSS 6.3

Backstage: Improper input validation in Confluence to Markdown scaffolder module

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content.

Patches

Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25

Workarounds

If unable to update immediately:

  • Restrict Confluence edit access to trusted users.
  • Review Confluence page content before running scaffolder templates against untrusted pages.

🎯 Affected products1

  • npm/@backstage/plugin-scaffolder-backend-module-confluence-to-markdown:< 0.3.25

🔗 References (5)