A malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs.
The attack requires: - The ability to register a template in the catalog - A victim who executes the malicious template
Patched in @backstage/plugin-scaffolder-backend version 3.1.4
{
"github_reviewed": true,
"github_reviewed_at": "2026-03-05T00:23:51Z",
"nvd_published_at": "2026-03-07T15:15:55Z",
"severity": "LOW",
"cwe_ids": [
"CWE-532"
]
}