GHSA-4xvq-3m68-h444

Suggest an improvement
Source
https://github.com/advisories/GHSA-4xvq-3m68-h444
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-4xvq-3m68-h444/GHSA-4xvq-3m68-h444.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4xvq-3m68-h444
Aliases
Published
2026-10-07T16:24:29Z
Modified
2026-10-07T16:30:05Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Backstage has sensitive information exposure in scaffolder task logs
Details

Impact

An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

  • Restrict scaffolder task creation and task-log reading to trusted users.
  • Avoid placing centrally managed sensitive values in inputs to actions that may be denied until upgrading.

References

Database specific
{
    "cwe_ids": [
        "CWE-532"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T16:24:29Z",
    "nvd_published_at": "2026-10-06T22:17:05Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-4xvq-3m68-h444/GHSA-4xvq-3m68-h444.json"