Sensitive Information Exposure in Backstage Plugin from Backstage
CVE-2026-106504
6.5MEDIUM
What is CVE-2026-106504?
The @backstage/plugin-scaffolder-backend package in Backstage allows authenticated users to create and read scaffolder tasks. However, prior to version 4.1.0, this package is susceptible to sensitive information exposure via task logs. In environments with restrictive action permissions, a user may inadvertently observe sensitive values if the input to a denied action includes such data. This vulnerability necessitates careful management of permissions and input values to prevent unauthorized information disclosure.
Affected Version(s)
backstage < 1.54.6
plugin-scaffolder-backend < 4.1.0
