CVE-2026-106506: Backstage: Improper input validation in scaffolder task list ordering
Impact
An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- At the gateway or reverse proxy, reject task-list requests that specify custom ordering, or allow ordering only by createdat, status, and createdby. - Restrict scaffolder task creation and task read permissions to trusted users, preferably using owner-based task-read conditions. - Disabling task recovery can reduce secret retention after a task is claimed, but it does not protect secrets in queued tasks and should not be treated as complete mitigation.
Other sources
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Configuration
Disable task recovery to reduce secret retention after a task is claimed; this does not protect secrets in queued tasks and is not a complete mitigation.
Backstage scaffolder task recovery = disabled - Compensating control
At the gateway or reverse proxy, reject scaffolder task-list requests that specify custom ordering, or allow ordering only by created_at, status, and created_by.
- Compensating control
Restrict scaffolder task creation and task-read permissions to trusted users, preferably using owner-based task-read conditions.
Event History
Frequently Asked Questions
Who can realistically exploit this issue?
An attacker must be an authenticated Backstage user with permission to create and read the relevant scaffolder tasks. They also need visibility of the target task.
What additional conditions are required to disclose confidential task data?
Task secrets must be retained, the attacker must know the secret structure, and exploitation requires repeated requests. The issue may allow inference of confidential task data only when these conditions are met.
Which versions are affected and what is the fix?
Versions of @backstage/plugin-scaffolder-backend prior to 4.1.0 are affected. Upgrade to version 4.1.0.