CVE-2025-55285: @backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly redacted. If ${{ secrets.x }} is not passed through to fetch:template there is no impact. This issue has been resolved in 2.1.1 of the scaffolder-backend plugin. A workaround for this issue involves Template Authors removing the use of ${{ secrets }} being used as an argument to fetch:template.
Other sources
Impact Duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly redacted. If you're not passing through ${{ secrets.x }} to fetch:template there is no impact.
Patches This issue has been resolved in 2.1.1 of the scaffolder-backend plugin.
Workarounds Template Authors can remove the use of ${{ secrets }} being used as an argument to fetch:template.
References If you have any questions or comments about this advisory:
Open an issue in the Backstage repository Visit our Discord, linked to in Backstage README
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55285?
CVE-2025-55285 has been identified as a medium severity vulnerability due to improper redaction of sensitive data.
How do I fix CVE-2025-55285?
To fix CVE-2025-55285, update the @backstage/plugin-scaffolder-backend to version 2.1.1 or later.
What software is affected by CVE-2025-55285?
CVE-2025-55285 affects the @backstage/plugin-scaffolder-backend prior to version 2.1.1.
What kind of data is exposed in CVE-2025-55285?
CVE-2025-55285 can expose secrets that are not properly redacted in the fetch:template action of the Scaffolder.
Is CVE-2025-55285 related to any other vulnerabilities?
CVE-2025-55285 is part of a broader concern regarding secure logging practices in software development.