REDHAT-BUG-2431878: Path Traversal

Published Jan 21, 2026
·
Updated

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the debug:log action by creating a symlink pointing to sensitive files (e.g., /etc/passwd, configuration files, secrets); delete arbitrary files via the fs:delete action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in @backstage/backend-defaults versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; @backstage/plugin-scaffolder-backend versions 2.2.2, 3.0.2, and 3.1.1; and @backstage/plugin-scaffolder-node versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.

Affected Software

3 affected components
npm/@backstage/backend-defaults><
npm/@backstage/plugin-scaffolder-backend><
npm/@backstage/plugin-scaffolder-node><

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @backstage/backend-defaults to a version that resolves this vulnerability.

    Fixed in 0.12.2
  2. Upgrade

    Upgrade @backstage/backend-defaults to a version that resolves this vulnerability.

    Fixed in 0.13.2
  3. Upgrade

    Upgrade @backstage/backend-defaults to a version that resolves this vulnerability.

    Fixed in 0.14.1
  4. Upgrade

    Upgrade @backstage/backend-defaults to a version that resolves this vulnerability.

    Fixed in 0.15.0
  5. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 2.2.2
  6. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 3.0.2
  7. Upgrade

    Upgrade @backstage/plugin-scaffolder-backend to a version that resolves this vulnerability.

    Fixed in 3.1.1
  8. Upgrade

    Upgrade @backstage/plugin-scaffolder-node to a version that resolves this vulnerability.

    Fixed in 0.11.2
  9. Upgrade

    Upgrade @backstage/plugin-scaffolder-node to a version that resolves this vulnerability.

    Fixed in 0.12.3
  10. Compensating control

    Follow the Backstage Threat Model recommendation to limit access to creating and updating Scaffolder templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.

Event History

Jan 21, 2026
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who is exposed to exploitation?

Any Backstage deployment in which users can create or execute Scaffolder templates is affected. An attacker needs access to create and execute a template to use the vulnerable actions or archive extraction paths.

2

What impact can a successful attacker have?

A malicious template can use symlinks to read arbitrary files through the debug:log action, delete files outside the workspace through fs:delete, or write files outside the workspace through crafted tar or zip archive extraction.

3

Which package versions contain fixes?

Fixed versions are @backstage/backend-defaults 0.12.2, 0.13.2, 0.14.1, and 0.15.0; @backstage/plugin-scaffolder-backend 2.2.2, 3.0.2, and 3.1.1; and @backstage/plugin-scaffolder-node 0.11.2 and 0.12.3. Upgrade to the applicable listed version or later.

4

What can be done if upgrading is not immediately possible?

Limit access to creating and updating templates, and restrict who can create and execute Scaffolder templates, following the Backstage Threat Model recommendations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203