Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Plugins
CVE-2026-106486

8.5HIGH

What is CVE-2026-106486?

In Backstage's Bitbucket scaffolder plugins, prior to version 0.3.10 for the cloud module and 0.2.25 for the server module, a path traversal vulnerability was identified. This flaw allows an authenticated user with the capability to execute a specific template to manipulate filesystem paths, potentially exposing sensitive data or compromising the integrity of the backend environment. The issue can arise when interacting with an allowed Bitbucket repository, leading to unauthorized access beyond the expected operational directory. This vulnerability has been addressed in the specified versions of the affected plugins.

Affected Version(s)

backstage < 1.54.6

plugin-scaffolder-backend-module-bitbucket-cloud < 0.3.10

plugin-scaffolder-backend-module-bitbucket-server < 0.2.25

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.