CVE-2026-106502
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user may retrieve backend-managed credentials used during task execution from affected task events. This issue is fixed in version 4.1.0.
532
Insertion of Sensitive Information into Log File
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
All platforms may be affected
https://github.com/backstage/backstage/commit/3f1e869708f002fb9838624b7379deb25…
https://github.com/backstage/backstage/releases/tag/v1.54.6
https://github.com/backstage/backstage/security/advisories/GHSA-95p4-vv4g-jxxm