Scaffolder actions that interact with source control systems may not consistently enforce the intended credential boundaries under certain configurations. An authenticated user could perform operations with broader access than intended.
@backstage/plugin-scaffolder-backend version 4.1.0@backstage/plugin-scaffolder-backend-module-azure version 0.2.25@backstage/plugin-scaffolder-backend-module-bitbucket-cloud version 0.3.10@backstage/plugin-scaffolder-backend-module-bitbucket-server version 0.2.25@backstage/plugin-scaffolder-backend-module-github version 0.9.13@backstage/plugin-scaffolder-backend-module-gitlab version 0.11.10The fix introduces a new configuration option that enforces user-provided credentials for supported SCM actions. The new behavior is opt-in for compatibility. After upgrading, set:
scaffolder:
requireScmUserCredentials: true
Before enabling this setting, review and update your templates as described in the software templates documentation referred to below.
If you cannot upgrade and enable the setting immediately:
{
"cwe_ids": [
"CWE-441",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T18:01:53Z",
"nvd_published_at": "2026-10-06T21:17:17Z",
"severity": "MODERATE"
}