An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources.
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
{
"cwe_ids": [
"CWE-178",
"CWE-284"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T17:59:08Z",
"nvd_published_at": "2026-10-06T22:17:05Z",
"severity": "HIGH"
}