GHSA-mfvq-x7vr-rgqg: Medium severity npm/@backstage/plugin-scaffolder-backend vulnerability

Published Oct 7, 2026
·
Updated

Impact

Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder templates are affected. A template author could cause secret-derived values used during template iteration to be persisted in task logs, exposing those values to users with access to the resulting task logs.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

- Restrict permission to create or update Template entities to fully trusted parties, as recommended by the Backstage threat model. - If that restriction cannot be guaranteed, remove sensitive values from scaffolder.defaultEnvironment.secrets until a patched version is available.

No complete workaround is known that preserves both untrusted template authoring and access to sensitive default-environment secrets.

Affected Software

1 affected componentFixes available
npm/@backstage/plugin-scaffolder-backend<4.1.0
4.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 4.1.0
  2. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 4.1.0
  3. Configuration

    Remove sensitive values from scaffolder.defaultEnvironment.secrets until the patched version is available.

    Backstage Scaffolder scaffolder.defaultEnvironment.secrets = remove sensitive values
  4. Compensating control

    Restrict permission to create or update Template entities to fully trusted parties.

Event History

Oct 7, 2026
Advisory Published
via GitHub·05:59 PM
Data Sourced
via GitHub·05:59 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Affected deployments both configure sensitive values in scaffolder.defaultEnvironment.secrets and permit an attacker to create or modify Scaffolder templates. Deployments that do not meet both conditions are not identified as affected by the advisory.

2

What access does an attacker need?

An attacker needs permission to create or update a Scaffolder Template entity. They can then author a template that causes secret-derived values used during template iteration to be written to task logs.

3

Who could view exposed secret values?

The secret-derived values may be exposed to users who have access to the resulting task logs. The advisory does not state that the attacker needs direct access to those logs to cause the disclosure.

4

What should be done if upgrading is not immediately possible?

Restrict Template entity creation and update permissions to fully trusted parties. If that cannot be ensured, remove sensitive values from scaffolder.defaultEnvironment.secrets; no complete workaround preserves both untrusted template authoring and sensitive default-environment secrets.

5

What version contains the fix?

The issue is patched in @backstage/plugin-scaffolder-backend version 4.1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203