CVE-2026-106459: Backstage: Improper input validation in Sentry scaffolder actions
Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to contact unintended destinations and disclose Sentry integration credentials. Subsequent impact depends on network reachability and the privileges granted to the configured token. This issue is fixed in version 0.3.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-sentryto a version that resolves this vulnerability.Fixed in 0.3.8
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated internal user must be able to execute the affected Sentry scaffolder actions. The issue is therefore relevant to Backstage deployments where such action execution rights are granted to users.
What can an attacker do with successful exploitation?
They may cause the backend to contact unintended destinations and disclose Sentry integration credentials. The resulting impact depends on what network destinations the backend can reach and the privileges assigned to the configured token.
Which package versions are affected and what version fixes the issue?
Versions from 0.3.0 through before 0.3.8 of @backstage/plugin-scaffolder-backend-module-sentry are affected. Version 0.3.8 fixes the issue.