Medium severity6.3NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-106559
CVE-2026-106559
Description
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper input validation in confluence to markdown scaffolder module. Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content. This issue is fixed in version 0.3.25.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <0.3.25
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.