GHSA-rq6q-wr2q-7pgp

Suggest an improvement
Source
https://github.com/advisories/GHSA-rq6q-wr2q-7pgp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rq6q-wr2q-7pgp
Aliases
Published
2026-01-21T22:36:36Z
Modified
2026-02-03T03:12:21Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L CVSS Calculator
Summary
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
Details

Impact

Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:

  1. Read arbitrary files via the debug:log action by creating a symlink pointing to sensitive files (e.g., /etc/passwd, configuration files, secrets)
  2. Delete arbitrary files via the fs:delete action by creating symlinks pointing outside the workspace
  3. Write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks

This affects any Backstage deployment where users can create or execute Scaffolder templates.

Patches

This vulnerability is fixed in the following package versions:

  • @backstage/backend-defaults version 0.12.2, 0.13.2, 0.14.1, 0.15.0
  • @backstage/plugin-scaffolder-backend version 2.2.2, 3.0.2, 3.1.1
  • @backstage/plugin-scaffolder-node version 0.11.2, 0.12.3

Users should upgrade to these versions or later.

Workarounds

  • Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates
  • Restrict who can create and execute Scaffolder templates using the permissions framework
  • Audit existing templates for symlink usage
  • Run Backstage in a containerized environment with limited filesystem access

References

Database specific
{
    "cwe_ids":  [
        "CWE-22",
        "CWE-59"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-01-21T22:36:36Z",
    "nvd_published_at":  "2026-01-21T23:15:53Z",
    "severity":  "HIGH"
}
References

Affected packages

npm
@backstage/backend-defaults

Package

Name
@backstage/backend-defaults
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/backend-defaults

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.12.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"
@backstage/backend-defaults

Package

Name
@backstage/backend-defaults
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/backend-defaults

Affected ranges

Type
SEMVER
Events
Introduced
0.13.0
Fixed
0.13.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"
@backstage/backend-defaults

Package

Name
@backstage/backend-defaults
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/backend-defaults

Affected ranges

Type
SEMVER
Events
Introduced
0.14.0
Fixed
0.14.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"
@backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"
@backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"
@backstage/plugin-scaffolder-backend

Package

Name
@backstage/plugin-scaffolder-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-backend

Affected ranges

Type
SEMVER
Events
Introduced
3.1.0
Fixed
3.1.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"
@backstage/plugin-scaffolder-node

Package

Name
@backstage/plugin-scaffolder-node
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-node

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.11.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"
@backstage/plugin-scaffolder-node

Package

Name
@backstage/plugin-scaffolder-node
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-scaffolder-node

Affected ranges

Type
SEMVER
Events
Introduced
0.12.0
Fixed
0.12.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"