CRITICAL
9.6 CVE-2026-106501 Published 6 Oct 2026
Backstage Scaffolder Backend Information Disclosure Vulnerability
Worried this affects your website?
Backstage, an open framework for building developer portals, is affected by a sensitive information exposure vulnerability in the scaffolder feature.
Prior to versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package may expose internal execution data to an authenticated Backstage user who can read another user's Scaffolder task.
- Affected versions: prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0
- Fixed versions: 3.3.1, 3.4.1, 4.0.3 and 4.1.0
- Impact: In deployments where the exposed data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service.
Reference: CVE-2026-106501 on NVD
← Back to Security News