GHSA-hmp2-4m7g-22cvHighCVSS 8.1

Backstage: Scaffolder action input authorization bypass

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

  • Restrict affected Scaffolder actions to trusted users and configure source-control integrations with least-privilege credentials.

🎯 Affected products4

  • npm/@backstage/plugin-scaffolder-backend:< 3.3.1
  • npm/@backstage/plugin-scaffolder-backend:>= 3.4.0, < 3.4.1
  • npm/@backstage/plugin-scaffolder-backend:>= 4.0.0, < 4.0.3
  • npm/@backstage/plugin-scaffolder-backend:>= 4.0.4, < 4.1.0

🔗 References (9)