GHSA-95p4-vv4g-jxxmMediumCVSS 5.3
Backstage may expose sensitive information in Scaffolder task failure events
🔗 CVE IDs covered (1)
📋 Description
Impact
Under specific template and failure conditions, an authenticated user may be able to retrieve sensitive values from Scaffolder task events. This can expose backend-managed credentials used during task execution.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict Scaffolder template execution and task-event access to trusted users until the patched version is deployed.
🎯 Affected products1
- npm/@backstage/plugin-scaffolder-backend:< 4.1.0
🔗 References (5)
- https://github.com/backstage/backstage/security/advisories/GHSA-95p4-vv4g-jxxm
- https://nvd.nist.gov/vuln/detail/CVE-2026-106502
- https://github.com/backstage/backstage/commit/3f1e869708f002fb9838624b7379deb251691b47
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-95p4-vv4g-jxxm