CVE-2026-106502: Sensitive Information Exposure in Backstage Scaffolder Backend
Vulnerability ID: CVE-2026-106502
CVSS Score: 5.3
Published: 2026-10-07
The @backstage/plugin-scaffolder-backend package prior to version 4.1.0 is vulnerable to sensitive information exposure in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user can retrieve backend-managed credentials, such as VCS access tokens and API keys, from affected task execution events and stored database logs. This vulnerability has been remediated in version 4.1.0 of the package and is bundled with the Backstage platform release v1.54.6.
TL;DR
Authenticated users can extract raw, unredacted backend-managed credentials from task failure logs and database events generated by failed Backstage Scaffolder workflows.
Technical Details
- CWE ID: CWE-532
- Attack Vector: Network (AV:N)
- CVSS Base Score: 5.3
- EPSS Score: 0.00284
- Impact: High Confidentiality Loss (C:H)
- Exploit Status: none
- CISA KEV Status: Not Listed
Affected Systems
- @backstage/plugin-scaffolder-backend
- Backstage Platform (Core Repository)
-
@backstage/plugin-scaffolder-backend: < 4.1.0 (Fixed in:
4.1.0) -
Backstage (Core Repository): < v1.54.6 (Fixed in:
v1.54.6)
Code Analysis
Commit: 3f1e869
scaffolder-backend: Redact secrets in task execution and checkpoint failures.
Mitigation Strategies
- Upgrade @backstage/plugin-scaffolder-backend package to version 4.1.0 or higher.
- Restrict read access to Scaffolder task execution events using Backstage Permissions API.
- Sanitize existing database tables to purge historical, unredacted secrets from task logs.
Remediation Steps:
- Open your Backstage repository root.
- Run the yarn workspace command to bump the package:
yarn workspace @backstage/plugin-scaffolder-backend upgrade @backstage/plugin-scaffolder-backend@4.1.0or runyarn backstage-cli versions:bumpto align with platform release v1.54.6. - Verify the update in your yarn.lock file.
- Execute database queries on the
task_eventstable to locate and erase any plaintext secrets logged prior to the upgrade. - Deploy the updated Backstage instance to staging and production environments.
References
Read the full report for CVE-2026-106502 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)