OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-106501: Backstage: Sensitive information exposure in Scaffolder

GitHub Advisories · officialPublished Oct 7, 2026Risk 50/100

### Impact An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service. ### Patches Patched in `@backstage/plugin-scaffolder-backend` version `4.1.0` ### Workarounds - Configure `scaffolder.task.read` with the `isTaskOwner` condition so users can only read tasks they created. - Restrict affected integrations and workflows to trusted operators until an upgrade is available.

Upgrade affected packages to a patched version: @backstage/plugin-scaffolder-backend 3.3.1, @backstage/plugin-scaffolder-backend 3.4.1, @backstage/plugin-scaffolder-backend 4.0.3, @backstage/plugin-scaffolder-backend 4.1.0.

Vendor
Not specified
Product
@backstage/plugin-scaffolder-backend
Exploitation
none known
Evidence
official
CVSS
9.6

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source