Improper Task State Validation in Backstage Scaffolder Backend Plugin Affecting Developer Portals
CVE-2026-106500
What is CVE-2026-106500?
The @backstage/plugin-scaffolder-backend package, used in Backstage developer portals, suffers from an improper task state validation issue. This vulnerability allows authenticated users with permissions to create and access Scaffolder tasks to manipulate files that are accessible to the Backstage backend under certain timing and deployment circumstances. If the backend application files are writable, this may lead to compromises in the confidentiality, integrity, and availability of backend resources. Users are advised to upgrade to the patched versions 3.3.1, 3.4.1, 4.0.3, or 4.1.0 to mitigate this risk.
Affected Version(s)
backstage < 1.49.6 < 1.49.6
backstage >= 1.50.0-next.0, < 1.50.5 < 1.50.0-next.0, 1.50.5
backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6
