GHSA-g2v8-7jhw-pp8p

Suggest an improvement
Source
https://github.com/advisories/GHSA-g2v8-7jhw-pp8p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g2v8-7jhw-pp8p/GHSA-g2v8-7jhw-pp8p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g2v8-7jhw-pp8p
Aliases
Published
2026-10-07T17:59:19Z
Modified
2026-10-07T18:15:10Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Backstage: Sensitive information exposure in Scaffolder
Details

Impact

An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

  • Configure scaffolder.task.read with the isTaskOwner condition so users can only read tasks they created.
  • Restrict affected integrations and workflows to trusted operators until an upgrade is available.
Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-201"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T17:59:19Z",
    "nvd_published_at": "2026-10-06T22:17:05Z",
    "severity": "CRITICAL"
}
References

Affected packages

npm
@backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g2v8-7jhw-pp8p/GHSA-g2v8-7jhw-pp8p.json"
@backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
3.4.0
Fixed
3.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g2v8-7jhw-pp8p/GHSA-g2v8-7jhw-pp8p.json"
@backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g2v8-7jhw-pp8p/GHSA-g2v8-7jhw-pp8p.json"
@backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
4.0.4
Fixed
4.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g2v8-7jhw-pp8p/GHSA-g2v8-7jhw-pp8p.json"