PT-2026-107303 · Backstage · Backstage

CVE-2026-106506

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Backstage versions prior to 4.1.0
Description The @backstage/plugin-scaffolder-backend package contains improper input validation regarding the ordering of scaffolder task lists. An authenticated user with permissions to create and read scaffolder tasks can potentially infer confidential task data. This requires the attacker to have visibility of a target task, knowledge of the secret structure, retained task secrets, and the ability to make repeated requests.
Recommendations Update to version 4.1.0.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106506
GHSA-VWP5-F99X-X3RQ

Affected Products

Backstage