Vulnerability GHSA-75qf-886x-5xf2

Medium Risk
MEDIUM RISK
CVSS Score: 6.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 hours ago
October 07, 2026 at 06:03 PM UTC
Backstage: Improper input validation in Confluence to Markdown scaffolder module
0.0.0-nightly-20230325022054 - 0.3.25-next.0
0.0.0-nightly-20230325022054 - 0.3.25-next.0

Summary

Backstage: Improper input validation in Confluence to Markdown scaffolder module

Details

Impact

Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content.

Patches

Patched in @backstage/plugin-scaffolder-backend-module-confluence-to-markdown version 0.3.25

Workarounds

If unable to update immediately:

  • Restrict Confluence edit access to trusted users.
  • Review Confluence page content before running scaffolder templates against untrusted pages.

Timeline

Published
3 hours ago
October 07, 2026 at 06:03 PM UTC
Fixed (0.3.25)
Unknown
Unknown
Last Modified
3 hours ago
October 07, 2026 at 06:15 PM UTC