CVE-2026-106501: Backstage: Sensitive information exposure in Scaffolder
### Impact An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service. ### Patches Patched in `@backstage/plugin-scaffolder-backend` version `4.1.0` ### Workarounds - Configure `scaffolder.task.read` with the `isTaskOwner` condition so users can only read tasks they created. - Restrict affected integrations and workflows to trusted operators until an upgrade is available.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/plugin-scaffolder-backend 3.3.1, @backstage/plugin-scaffolder-backend 3.4.1, @backstage/plugin-scaffolder-backend 4.0.3, @backstage/plugin-scaffolder-backend 4.1.0.
Technical details
- Vendor
- Not specified
- Product
- @backstage/plugin-scaffolder-backend
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source