GHSA-95p4-vv4g-jxxm

Suggest an improvement
Source
https://github.com/advisories/GHSA-95p4-vv4g-jxxm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-95p4-vv4g-jxxm/GHSA-95p4-vv4g-jxxm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-95p4-vv4g-jxxm
Aliases
Published
2026-10-07T16:24:51Z
Modified
2026-10-07T16:30:06Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Backstage may expose sensitive information in Scaffolder task failure events
Details

Impact

Under specific template and failure conditions, an authenticated user may be able to retrieve sensitive values from Scaffolder task events. This can expose backend-managed credentials used during task execution.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

  • Restrict Scaffolder template execution and task-event access to trusted users until the patched version is deployed.
Database specific
{
    "cwe_ids": [
        "CWE-532"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T16:24:51Z",
    "nvd_published_at": "2026-10-06T22:17:05Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-95p4-vv4g-jxxm/GHSA-95p4-vv4g-jxxm.json"