GHSA-g734-fhp4-7mfp: Infoleak

Published Oct 7, 2026
·
Updated

Impact

An authenticated internal user who can execute the affected actions may cause the backend to contact unintended destinations and disclose Sentry integration credentials. Subsequent impact depends on network reachability and the privileges granted to the configured token.

Patches

Upgrade @backstage/plugin-scaffolder-backend-module-sentry to version 0.3.8 or later. The fixed package is available in Backstage v1.54.8 and Backstage v1.55.0.

The update removes custom action-level apiBaseUrl values. Move any such value to scaffolder.sentry.apiBaseUrl before upgrading.

Workarounds

- Disable the affected actions until the patched package is deployed. - Restrict scaffolder.action.execute permission for the affected Sentry actions to trusted users and templates.

Affected Software

1 affected componentFixes available
npm/@backstage/plugin-scaffolder-backend-module-sentry>=0.3.0<0.3.8
0.3.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend-module-sentry to a version that resolves this vulnerability.

    Fixed in 0.3.8
  2. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend-module-sentry to a version that resolves this vulnerability.

    Fixed in 0.3.8
  3. Configuration

    Restrict scaffolder.action.execute permission for the affected Sentry actions to trusted users and templates.

    Backstage Sentry scaffolder scaffolder.action.execute permission = trusted users and templates only
  4. Configuration

    Move any custom action-level apiBaseUrl value to scaffolder.sentry.apiBaseUrl before upgrading.

    Backstage Sentry scaffolder scaffolder.sentry.apiBaseUrl = the custom API base URL
  5. Compensating control

    Disable the affected Sentry actions until the patched package is deployed.

Event History

Oct 7, 2026
Advisory Published
via GitHub·08:25 PM
Data Sourced
via GitHub·08:25 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated internal user who can execute the affected Sentry actions can exploit it. Access to the scaffolder.action.execute permission for those actions is the relevant control point.

2

What could an attacker gain or do?

They may cause the backend to contact unintended destinations and disclose Sentry integration credentials. The resulting impact depends on what network locations the backend can reach and the privileges of the configured token.

3

What configuration change is required when upgrading?

Upgrade @backstage/plugin-scaffolder-backend-module-sentry to 0.3.8 or later. Before upgrading, move any custom action-level apiBaseUrl setting to scaffolder.sentry.apiBaseUrl, because the update removes custom action-level apiBaseUrl values.

4

What can be done before a patch is deployed?

Disable the affected actions, or restrict scaffolder.action.execute permission for the affected Sentry actions to trusted users and templates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203