GHSA-7hfw-grcm-cqm6: Medium severity npm/@backstage/plugin-scaffolder-backend vulnerability

Published Oct 7, 2026
·
Updated

Impact

An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a deployment's permission policy. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

- Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy to users who are permitted to view all tasks. - Avoid placing sensitive values in template input parameters until the patched package is deployed.

Affected Software

1 affected componentFixes available
npm/@backstage/plugin-scaffolder-backend<4.1.0
4.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 4.1.0
  2. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 4.1.0
  3. Compensating control

    Avoid placing sensitive values in template input parameters until the patched package is deployed.

  4. Compensating control

    Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy to users permitted to view all tasks.

Event History

Oct 7, 2026
Advisory Published
via GitHub·05:58 PM
Data Sourced
via GitHub·05:58 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated internal user may be able to exploit it. The issue concerns users who can reach the scaffolder task-list endpoint but are not intended to view all scaffolder tasks under the deployment's permission policy.

2

What information could be exposed?

The affected response may expose metadata for scaffolder tasks outside the intended visibility policy. Stored task secrets are not included, and no integrity or availability impact was identified.

3

Are default deployments affected?

The provided information does not identify whether a default configuration is affected. Exposure depends on access to the scaffolder task-list endpoint and the deployment's task visibility permission policy.

4

What can be done before upgrading?

Restrict the scaffolder task-list endpoint at the ingress or authenticating proxy so that only users permitted to view all tasks can access it. Avoid putting sensitive values in template input parameters until the patched package is deployed.

5

What version contains the fix?

The issue is patched in @backstage/plugin-scaffolder-backend version 4.1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203