CVE-2026-106500: Backstage: Improper task state validation in Scaffolder backend
Impact
An authenticated user with permission to create and access Scaffolder tasks may, under specific timing and deployment conditions, affect files accessible to the Backstage backend. If backend application files are writable, the confidentiality, integrity, and availability of the backend may be compromised.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict Scaffolder task creation and task-read permissions to trusted users through the permission policy. - Limit who can register or modify templates and which Scaffolder actions may execute. - Run backend application files read-only outside a dedicated, least-privilege Scaffolder working directory.
References
- Authorizing Scaffolder tasks, parameters, steps, and actions
Other sources
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific timing and deployment conditions, affect files accessible to the Backstage backend. If backend application files are writable, the confidentiality, integrity, and availability of the backend may be compromised. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.3.1 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.4.1 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.0.3 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Configuration
Restrict Scaffolder task creation and task-read permissions to trusted users through the permission policy.
Backstage permission policy Scaffolder task creation and task-read permissions = trusted users only - Compensating control
Limit who can register or modify templates and which Scaffolder actions may execute.
- Compensating control
Run backend application files read-only outside a dedicated, least-privilege Scaffolder working directory.
Event History
Frequently Asked Questions
Who is exposed to exploitation?
An authenticated user who has permission to create and access Scaffolder tasks is required. Exploitation also depends on specific timing and deployment conditions.
Are all affected Backstage deployments equally at risk?
No. The most severe impact requires backend application files to be writable. In that condition, the backend's confidentiality, integrity, and availability may be compromised.
Which package versions contain fixes?
The issue is fixed in @backstage/plugin-scaffolder-backend versions 3.3.1, 3.4.1, 4.0.3, and 4.1.0.