GHSA-7hfw-grcm-cqm6MediumCVSS 4.3

Backstage: Incorrect authorization in scaffolder task listing

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a deployment's permission policy. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

  • Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy to users who are permitted to view all tasks.
  • Avoid placing sensitive values in template input parameters until the patched package is deployed.

🎯 Affected products1

  • npm/@backstage/plugin-scaffolder-backend:< 4.1.0

🔗 References (5)