Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Plugins
CVE-2026-106486
What is CVE-2026-106486?
In Backstage's Bitbucket scaffolder plugins, prior to version 0.3.10 for the cloud module and 0.2.25 for the server module, a path traversal vulnerability was identified. This flaw allows an authenticated user with the capability to execute a specific template to manipulate filesystem paths, potentially exposing sensitive data or compromising the integrity of the backend environment. The issue can arise when interacting with an allowed Bitbucket repository, leading to unauthorized access beyond the expected operational directory. This vulnerability has been addressed in the specified versions of the affected plugins.
Affected Version(s)
backstage < 1.54.6
plugin-scaffolder-backend-module-bitbucket-cloud < 0.3.10
plugin-scaffolder-backend-module-bitbucket-server < 0.2.25
