VYPR

@backstage/plugin-scaffolder-backend

by Backstage

CVEs (8)

  • CVE-2026-106501CriOct 6, 2026
    risk 0.55cvss 9.6epss —

    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's…

  • CVE-2026-106500HigOct 6, 2026
    risk 0.48cvss 8.5epss —

    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access…

  • CVE-2026-106503HigOct 6, 2026
    risk 0.46cvss 8.1epss —

    Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates…

  • CVE-2026-106504MedOct 6, 2026
    risk 0.35cvss 6.5epss —

    Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to…

  • CVE-2026-106506MedOct 6, 2026
    risk 0.27cvss 5.3epss —

    Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant…

  • CVE-2026-106502MedOct 6, 2026
    risk 0.27cvss 5.3epss —

    Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user may…

  • CVE-2026-106499MedOct 6, 2026
    risk 0.25cvss 4.9epss —

    Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an…

  • CVE-2026-106461MedOct 6, 2026
    risk 0.21cvss 4.3epss —

    Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An authenticated internal user may be able to view metadata for scaffolder tasks…