Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder templates are affected. A template author could cause secret-derived values used during template iteration to be persisted in task logs, exposing those values to users with access to the resulting task logs.
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
scaffolder.defaultEnvironment.secrets until a patched version is available.No complete workaround is known that preserves both untrusted template authoring and access to sensitive default-environment secrets.
{
"cwe_ids": [
"CWE-532"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T17:59:14Z",
"nvd_published_at": "2026-10-06T22:17:04Z",
"severity": "MODERATE"
}