High severity7.1NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-106560
CVE-2026-106560
Description
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process. This issue is fixed in version 0.3.25.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <0.3.25
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.