GHSA-29gx-h2m3-xw44: Medium severity npm/@backstage/plugin-scaffolder-backend-module-bitbucket-server vulnerability

Published Oct 7, 2026
·
Updated

Impact

Scaffolder actions that interact with source control systems may not consistently enforce the intended credential boundaries under certain configurations. An authenticated user could perform operations with broader access than intended.

Patches

- @backstage/plugin-scaffolder-backend version 4.1.0 - @backstage/plugin-scaffolder-backend-module-azure version 0.2.25 - @backstage/plugin-scaffolder-backend-module-bitbucket-cloud version 0.3.10 - @backstage/plugin-scaffolder-backend-module-bitbucket-server version 0.2.25 - @backstage/plugin-scaffolder-backend-module-github version 0.9.13 - @backstage/plugin-scaffolder-backend-module-gitlab version 0.11.10

The fix introduces a new configuration option that enforces user-provided credentials for supported SCM actions. The new behavior is opt-in for compatibility. After upgrading, set:

yaml scaffolder: requireScmUserCredentials: true

Before enabling this setting, review and update your templates as described in the software templates documentation referred to below.

Workarounds

If you cannot upgrade and enable the setting immediately:

- Restrict who can create Scaffolder tasks and which templates they can execute. - Limit SCM integration credentials to the minimum repository read and mutation permissions required. - Remove integration credentials for SCM hosts where all required operations can use explicitly supplied user tokens.

Affected Software

6 affected componentsFixes available
npm/@backstage/plugin-scaffolder-backend-module-bitbucket-server<0.2.25
0.2.25
npm/@backstage/plugin-scaffolder-backend-module-bitbucket-cloud<0.3.10
0.3.10
npm/@backstage/plugin-scaffolder-backend-module-azure<0.2.25
0.2.25
npm/@backstage/plugin-scaffolder-backend-module-gitlab<0.11.10
0.11.10
npm/@backstage/plugin-scaffolder-backend-module-github<0.9.13
0.9.13
npm/@backstage/plugin-scaffolder-backend<4.1.0
4.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend-module-bitbucket-server to a version that resolves this vulnerability.

    Fixed in 0.2.25
  2. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend-module-bitbucket-cloud to a version that resolves this vulnerability.

    Fixed in 0.3.10
  3. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend-module-azure to a version that resolves this vulnerability.

    Fixed in 0.2.25
  4. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend-module-gitlab to a version that resolves this vulnerability.

    Fixed in 0.11.10
  5. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend-module-github to a version that resolves this vulnerability.

    Fixed in 0.9.13
  6. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 4.1.0
  7. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend-module-azure to a version that resolves this vulnerability.

    Fixed in 0.2.25
  8. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend-module-bitbucket-cloud to a version that resolves this vulnerability.

    Fixed in 0.3.10
  9. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend-module-bitbucket-server to a version that resolves this vulnerability.

    Fixed in 0.2.25
  10. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend-module-github to a version that resolves this vulnerability.

    Fixed in 0.9.13
  11. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend-module-gitlab to a version that resolves this vulnerability.

    Fixed in 0.11.10
  12. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 4.1.0
  13. Configuration

    Set requireScmUserCredentials to true to enforce user-provided credentials for supported SCM actions; review and update templates before enabling it.

    Backstage Scaffolder requireScmUserCredentials = true
  14. Compensating control

    Limit SCM integration credentials to the minimum repository read and mutation permissions required.

  15. Compensating control

    Remove integration credentials for SCM hosts where all required operations can use explicitly supplied user tokens.

  16. Compensating control

    Restrict who can create Scaffolder tasks and which templates they can execute.

Event History

Oct 7, 2026
Advisory Published
via GitHub·06:01 PM
Data Sourced
via GitHub·06:01 PM
DescriptionSeverityWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203