Vulnerability GHSA-75qf-886x-5xf2
Medium Risk
MEDIUM RISK
CVSS Score: 6.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
October 07, 2026 at 06:03 PM UTC
Backstage: Improper input validation in Confluence to Markdown scaffolder module
0.0.0-nightly-20230325022054 - 0.3.25-next.0
0.0.0-nightly-20230325022054 - 0.3.25-next.0
Summary
Backstage: Improper input validation in Confluence to Markdown scaffolder module
Details
Impact
Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content.
Patches
Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25
Workarounds
If unable to update immediately:
- Restrict Confluence edit access to trusted users.
- Review Confluence page content before running scaffolder templates against untrusted pages.
Impacted packages
Timeline
Published
3 hours ago
October 07, 2026 at 06:03 PM UTC
Fixed (0.3.25)
Unknown
Unknown
Last Modified
3 hours ago
October 07, 2026 at 06:15 PM UTC