Improper Input Validation in Scaffolder Plugin for Backstage by Spotify
CVE-2026-106506

5.3MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106506?

The @backstage/plugin-scaffolder-backend package in the Backstage framework exhibits an improper input validation vulnerability prior to version 4.1.0. This issue allows authenticated users who possess permissions to create and access scaffolder tasks to potentially infer sensitive task information under certain conditions. To successfully exploit this vulnerability, an attacker must have access to retained task secrets, the visibility of a target task, knowledge of the task's secret structure, and the ability to make repeated requests. This flaw underscores the importance of validating user input rigorously to prevent unauthorized data exposure.

Affected Version(s)

backstage < 1.54.6

plugin-scaffolder-backend < 4.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.