Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content.
Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25
If unable to update immediately:
{
"cwe_ids": [
"CWE-22",
"CWE-73"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T18:03:06Z",
"nvd_published_at": "2026-10-07T15:17:17Z",
"severity": "MODERATE"
}