Improper Input Validation in Backstage Plugin by Spotify
CVE-2026-106559

6.3MEDIUM

What is CVE-2026-106559?

The Backstage framework, designed for developing developer portals, contains a security issue in the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package prior to version 0.3.25. This vulnerability arises from improper input validation within the Confluence to Markdown scaffolder module, potentially allowing attackers to manipulate file write operations during the execution of templates. For successful exploitation, a Backstage user must run a template that processes Confluence content compromised by an attacker. The vulnerability has been addressed in version 0.3.25.

Affected Version(s)

backstage < 1.54.6

plugin-scaffolder-backend-module-confluence-to-markdown < 0.3.25

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.