CVE-2026-106560: Backstage: Improper repository path validation in a Scaffolder backend module
Impact
An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process.
Patches
Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25
Workarounds
- Restrict execution of templates using the affected action to trusted users. - Remove or disable the affected action until the patched package is deployed.
Other sources
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process. This issue is fixed in version 0.3.25.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backend-module-confluence-to-markdownto a version that resolves this vulnerability.Fixed in 0.3.25 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backend-module-confluence-to-markdownto a version that resolves this vulnerability.Fixed in 0.3.25 - Configuration
Remove or disable the affected action until the patched package is deployed.
Backstage Scaffolder affected action = disabled - Compensating control
Restrict execution of templates using the affected action to trusted users.
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user must be able to execute an affected Scaffolder template and control the repository file location used by that template. The issue affects the confluence-to-markdown Scaffolder backend module before version 0.3.25.
What is the potential impact?
An attacker may cause generated content to be written outside the Scaffolder task workspace. Writes are limited to locations that are writable by the Backstage backend process.
What should teams do to remediate it?
Upgrade @backstage/plugin-scaffolder-backend-module-confluence-to-markdown to version 0.3.25 or later. The issue is fixed in version 0.3.25.
What can be done if the upgrade cannot be applied immediately?
Restrict access to execution of affected templates and prevent untrusted users from controlling repository file locations. Limit filesystem write permissions of the Backstage backend process to reduce the locations that could be targeted.