Under specific template and failure conditions, an authenticated user may be able to retrieve sensitive values from Scaffolder task events. This can expose backend-managed credentials used during task execution.
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
{
"cwe_ids": [
"CWE-532"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T16:24:51Z",
"nvd_published_at": "2026-10-06T22:17:05Z",
"severity": "MODERATE"
}