CVE-2026-106486: Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions
Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect paths outside the expected working area, potentially compromising backend confidentiality, integrity, or availability. This issue is fixed in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud 0.3.10 and @backstage/plugin-scaffolder-backend-module-bitbucket-server 0.2.25.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-bitbucket-cloudto a version that resolves this vulnerability.Fixed in 0.3.10 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-bitbucket-serverto a version that resolves this vulnerability.Fixed in 0.2.25
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using @backstage/plugin-scaffolder-backend-module-bitbucket-cloud before 0.3.10 or @backstage/plugin-scaffolder-backend-module-bitbucket-server before 0.2.25 are affected when they expose eligible Bitbucket pull-request Scaffolder actions.
What access does an attacker need?
An attacker must be authenticated, able to execute an eligible template, and able to influence an allowed Bitbucket repository. No user interaction is required.
What is the immediate remediation?
Upgrade @backstage/plugin-scaffolder-backend-module-bitbucket-cloud to 0.3.10 or later, and @backstage/plugin-scaffolder-backend-module-bitbucket-server to 0.2.25 or later, as applicable.
How can exposure be reduced before upgrading?
Restrict access to eligible Scaffolder templates and limit which users can influence allowed Bitbucket repositories. This reduces the set of authenticated users able to meet the exploitation prerequisites.