GHSA-75qf-886x-5xf2

Suggest an improvement
Source
https://github.com/advisories/GHSA-75qf-886x-5xf2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-75qf-886x-5xf2/GHSA-75qf-886x-5xf2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-75qf-886x-5xf2
Aliases
Published
2026-10-07T18:03:06Z
Modified
2026-10-07T18:15:12Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L CVSS Calculator
Summary
Backstage: Improper input validation in Confluence to Markdown scaffolder module
Details

Impact

Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content.

Patches

Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25

Workarounds

If unable to update immediately:

  • Restrict Confluence edit access to trusted users.
  • Review Confluence page content before running scaffolder templates against untrusted pages.
Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-73"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T18:03:06Z",
    "nvd_published_at": "2026-10-07T15:17:17Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @backstage/plugin-scaffolder-backend-module-confluence-to-markdown

Package

Name
@backstage/plugin-scaffolder-backend-module-confluence-to-markdown
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend-module-confluence-to-markdown

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.3.25

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-75qf-886x-5xf2/GHSA-75qf-886x-5xf2.json"