High severity8.5NVD Advisory· Published Oct 6, 2026
CVE-2026-106500
CVE-2026-106500
Description
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific timing and deployment conditions, affect files accessible to the Backstage backend. If backend application files are writable, the confidentiality, integrity, and availability of the backend may be compromised. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
Affected products
2- Range: <3.3.1, <3.4.1, <4.0.3, <4.1.0
Patches
Vulnerability mechanics
References
7- github.com/backstage/backstage/commit/0d24f1b8701f3dde6cd597f81997c1ea873a43aenvd
- github.com/backstage/backstage/commit/56be299dd3ef6706e13e76ea2f8a9b0dd0b6413dnvd
- github.com/backstage/backstage/commit/9e86c95a1a3ddfd54db03731cd8678aa63495175nvd
- github.com/backstage/backstage/releases/tag/v1.49.6nvd
- github.com/backstage/backstage/releases/tag/v1.50.5nvd
- github.com/backstage/backstage/releases/tag/v1.54.6nvd
- github.com/backstage/backstage/security/advisories/GHSA-xvgh-hmx8-9xxfnvd
News mentions
0No linked articles in our index yet.