Improper Input Validation in Scaffolder Plugin for Backstage by Spotify
CVE-2026-106506
5.3MEDIUM
What is CVE-2026-106506?
The @backstage/plugin-scaffolder-backend package in the Backstage framework exhibits an improper input validation vulnerability prior to version 4.1.0. This issue allows authenticated users who possess permissions to create and access scaffolder tasks to potentially infer sensitive task information under certain conditions. To successfully exploit this vulnerability, an attacker must have access to retained task secrets, the visibility of a target task, knowledge of the task's secret structure, and the ability to make repeated requests. This flaw underscores the importance of validating user input rigorously to prevent unauthorized data exposure.
Affected Version(s)
backstage < 1.54.6
plugin-scaffolder-backend < 4.1.0
