CVE-2026-106504: Backstage: Sensitive information exposure in scaffolder task logs
Impact
An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict scaffolder task creation and task-log reading to trusted users. - Avoid placing centrally managed sensitive values in inputs to actions that may be denied until upgrading.
References
- Backstage threat model - Backstage permissions overview
Other sources
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value. This issue is fixed in version 4.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Compensating control
Avoid placing centrally managed sensitive values in inputs to actions that may be denied until upgrading.
- Compensating control
Restrict scaffolder task creation and task-log reading to trusted users.
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user must be able to create scaffolder tasks and read their task logs. The exposure is relevant in deployments that use restrictive action permissions and have affected templates.
What conditions are required for sensitive data to appear in a task log?
Exploitation requires an action to be denied while its input contains a sensitive value. Under those conditions, the value may be observable in the scaffolder task logs.
Are default deployments necessarily affected?
The available information identifies restrictive action permissions and affected templates as required conditions. It does not establish that default configurations are affected.
What version fixes the issue?
Upgrade @backstage/plugin-scaffolder-backend to version 4.1.0 or later. Versions prior to 4.1.0 are affected.