GHSA-g8rx-f7m5-7794: Path Traversal

Published Oct 7, 2026
·
Updated

Impact

An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect filesystem paths outside the expected working area. Depending on the backend deployment, this could compromise backend confidentiality, integrity, or availability.

Patches

- @backstage/plugin-scaffolder-backend-module-bitbucket-cloud version 0.3.10 - @backstage/plugin-scaffolder-backend-module-bitbucket-server version 0.2.25

Workarounds

- Restrict execution of affected Scaffolder templates to trusted users. - Avoid templates that accept user-controlled target repositories for these actions.

Affected Software

2 affected componentsFixes available
npm/@backstage/plugin-scaffolder-backend-module-bitbucket-server<0.2.25
0.2.25
npm/@backstage/plugin-scaffolder-backend-module-bitbucket-cloud<0.3.10
0.3.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend-module-bitbucket-server to a version that resolves this vulnerability.

    Fixed in 0.2.25
  2. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend-module-bitbucket-cloud to a version that resolves this vulnerability.

    Fixed in 0.3.10
  3. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend-module-bitbucket-cloud to a version that resolves this vulnerability.

    Fixed in 0.3.10
  4. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend-module-bitbucket-server to a version that resolves this vulnerability.

    Fixed in 0.2.25
  5. Compensating control

    Avoid templates that accept user-controlled target repositories for these actions.

  6. Compensating control

    Restrict execution of affected Scaffolder templates to trusted users.

Event History

Oct 7, 2026
Advisory Published
via GitHub·06:01 PM
Data Sourced
via GitHub·06:01 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments using the affected Bitbucket Cloud or Bitbucket Server Scaffolder backend modules are exposed when an authenticated user can execute an eligible template and influence an allowed Bitbucket repository. The impact depends on the backend deployment, and may affect confidentiality, integrity, or availability.

2

What access does an attacker need?

An attacker needs authenticated access, permission to execute an eligible Scaffolder template, and the ability to influence an allowed Bitbucket repository. User interaction is not required.

3

Which versions include fixes?

Fixed versions are @backstage/plugin-scaffolder-backend-module-bitbucket-cloud 0.3.10 and @backstage/plugin-scaffolder-backend-module-bitbucket-server 0.2.25.

4

What can be done if patching cannot happen immediately?

Restrict execution of affected Scaffolder templates to trusted users. Also avoid templates that accept user-controlled target repositories for the affected actions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203