Medium severity5.3NVD Advisory· Published Oct 6, 2026
CVE-2026-106502
CVE-2026-106502
Description
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user may retrieve backend-managed credentials used during task execution from affected task events. This issue is fixed in version 4.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <4.1.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.