Sensitive Information Exposure in Backstage Plugin by Backstage
CVE-2026-106502
5.3MEDIUM
What is CVE-2026-106502?
The @backstage/plugin-scaffolder-backend is susceptible to a vulnerability that may expose sensitive backend-managed credentials during task execution failures. Specifically, under certain template configurations and failure scenarios, authenticated users could access sensitive data from task failure events. This issue highlights the importance of ensuring proper access controls and integrity measures, and has been addressed in version 4.1.0 of the plugin. For more detailed information, please refer to the official advisory.
Affected Version(s)
backstage < 1.54.6
plugin-scaffolder-backend < 4.1.0
