Vulnerability GHSA-8qp7-fhr9-fw53
Low Risk
LOW RISK
CVSS Score: 2.0
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
7 months ago
March 05, 2026 at 12:23 AM UTC
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
0.0.0-nightly-202010102951 - 3.1.4-next.0
0.0.0-nightly-202010102951 - 3.1.4-next.0
Summary
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
Details
Impact
A malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs.
The attack requires:
- The ability to register a template in the catalog
- A victim who executes the malicious template
Patches
Patched in @backstage/plugin-scaffolder-backend version 3.1.4
Workarounds
- Implement a custom permission policy that restricts scaffolder.task.read so users can only read their own task logs
- Restrict who can register templates in the catalog to trusted users only
Resources
- Backstage Scaffolder permissions documentation: https://backstage.io/docs/permissions/plugin-authors/01-setup/
- Backstage Threat Model: https://backstage.io/docs/overview/threat-model/
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
1 hour ago
Backstage: Incorrect authorization in scaffolder task listing
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-7hfw-grcm-cqm6
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-7hfw-grcm-cqm6
Medium Risk
3 hours ago
Backstage may expose sensitive information in Scaffolder task failure events
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-95p4-vv4g-jxxm
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-95p4-vv4g-jxxm
Medium Risk
3 hours ago
Backstage has sensitive information exposure in scaffolder task logs
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-4xvq-3m68-h444
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-4xvq-3m68-h444
Medium Risk
3 hours ago
Backstage has improper input validation in scaffolder task list ordering
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-vwp5-f99x-x3rq
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-vwp5-f99x-x3rq
Medium Risk
6 months ago
@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint
3.1.0 - 3.1.4 GHSA-8wq8-6859-qx77
3.1.0 - 3.1.4 GHSA-8wq8-6859-qx77
Impacted packages
Timeline
Published
7 months ago
March 05, 2026 at 12:23 AM UTC
Fixed (3.1.4)
7 months ago
March 04, 2026 at 07:36 AM UTC
Last Modified
7 months ago
March 09, 2026 at 04:02 PM UTC