GHSA-hmp2-4m7g-22cvHighCVSS 8.1
Backstage: Scaffolder action input authorization bypass
🔗 CVE IDs covered (1)
📋 Description
Impact
An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict affected Scaffolder actions to trusted users and configure source-control integrations with least-privilege credentials.
🎯 Affected products4
- npm/@backstage/plugin-scaffolder-backend:< 3.3.1
- npm/@backstage/plugin-scaffolder-backend:>= 3.4.0, < 3.4.1
- npm/@backstage/plugin-scaffolder-backend:>= 4.0.0, < 4.0.3
- npm/@backstage/plugin-scaffolder-backend:>= 4.0.4, < 4.1.0
🔗 References (9)
- https://github.com/backstage/backstage/security/advisories/GHSA-hmp2-4m7g-22cv
- https://nvd.nist.gov/vuln/detail/CVE-2026-106503
- https://github.com/backstage/backstage/commit/11c1384c0649b8ab26391c6a4e4f34b80ab0d188
- https://github.com/backstage/backstage/commit/a91ed72d540e80b62a73b39bb1563ff5018d52d1
- https://github.com/backstage/backstage/commit/e307e4f487103d815e484291b3fda778ab9983bf
- https://github.com/backstage/backstage/releases/tag/v1.49.6
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-hmp2-4m7g-22cv