PT-2026-107534 · Backstage · Plugin-Scaffolder-Backend-Module-Confluence-To-Markdown

CVE-2026-106559

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions @backstage/plugin-scaffolder-backend-module-confluence-to-markdown versions prior to 0.3.25
Description Improper input validation in the Confluence to Markdown scaffolder module allows an attacker to influence file write operations during template execution. This occurs when a user runs a template that processes Confluence content influenced by an attacker.
Recommendations Update @backstage/plugin-scaffolder-backend-module-confluence-to-markdown to version 0.3.25. Restrict Confluence edit access to trusted users. Review Confluence page content before running scaffolder templates against untrusted pages.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106559
GHSA-75QF-886X-5XF2

Affected Products

Plugin-Scaffolder-Backend-Module-Confluence-To-Markdown