CVE-2025-55285: @backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`

Published Aug 15, 2025
·
Updated

@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly redacted. If ${{ secrets.x }} is not passed through to fetch:template there is no impact. This issue has been resolved in 2.1.1 of the scaffolder-backend plugin. A workaround for this issue involves Template Authors removing the use of ${{ secrets }} being used as an argument to fetch:template.

Other sources

Impact Duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly redacted. If you're not passing through ${{ secrets.x }} to fetch:template there is no impact.

Patches This issue has been resolved in 2.1.1 of the scaffolder-backend plugin.

Workarounds Template Authors can remove the use of ${{ secrets }} being used as an argument to fetch:template.

References If you have any questions or comments about this advisory:

Open an issue in the Backstage repository Visit our Discord, linked to in Backstage README

— GitHub

Affected Software

2 affected componentsFixes available
Backstage @backstage/plugin-scaffolder-backend<2.1.1
npm/@backstage/plugin-scaffolder-backend<=2.1.0
2.1.1

Event History

Aug 15, 2025
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:43 PM
Data Sourced
via GitHub·06:43 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-55285?

CVE-2025-55285 has been identified as a medium severity vulnerability due to improper redaction of sensitive data.

2

How do I fix CVE-2025-55285?

To fix CVE-2025-55285, update the @backstage/plugin-scaffolder-backend to version 2.1.1 or later.

3

What software is affected by CVE-2025-55285?

CVE-2025-55285 affects the @backstage/plugin-scaffolder-backend prior to version 2.1.1.

4

What kind of data is exposed in CVE-2025-55285?

CVE-2025-55285 can expose secrets that are not properly redacted in the fetch:template action of the Scaffolder.

5

Is CVE-2025-55285 related to any other vulnerabilities?

CVE-2025-55285 is part of a broader concern regarding secure logging practices in software development.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203