An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value.
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
{
"cwe_ids": [
"CWE-532"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T16:24:29Z",
"nvd_published_at": "2026-10-06T22:17:05Z",
"severity": "MODERATE"
}