CVE-2026-106502: Backstage: Sensitive information may be exposed in Scaffolder task failure events
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user may retrieve backend-managed credentials used during task execution from affected task events. This issue is fixed in version 4.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0
Event History
Frequently Asked Questions
Who can retrieve the exposed credentials?
An authenticated user may retrieve backend-managed credentials from affected Scaffolder task failure events. Exploitation requires specific template and failure conditions.
What versions are affected and what fixes the issue?
Versions of @backstage/plugin-scaffolder-backend prior to 4.1.0 are affected. Upgrade the package to version 4.1.0 to fix the issue.