PT-2026-107534 · Backstage · Plugin-Scaffolder-Backend-Module-Confluence-To-Markdown
CVE-2026-106559
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
@backstage/plugin-scaffolder-backend-module-confluence-to-markdown versions prior to 0.3.25
Description
Improper input validation in the Confluence to Markdown scaffolder module allows an attacker to influence file write operations during template execution. This occurs when a user runs a template that processes Confluence content influenced by an attacker.
Recommendations
Update @backstage/plugin-scaffolder-backend-module-confluence-to-markdown to version 0.3.25.
Restrict Confluence edit access to trusted users.
Review Confluence page content before running scaffolder templates against untrusted pages.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plugin-Scaffolder-Backend-Module-Confluence-To-Markdown