Vulnerability GHSA-95p4-vv4g-jxxm

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
October 07, 2026 at 04:24 PM UTC
Backstage may expose sensitive information in Scaffolder task failure events
0.0.0-nightly-202010102951 - 4.1.0-next.0
0.0.0-nightly-202010102951 - 4.1.0-next.0

Summary

Backstage may expose sensitive information in Scaffolder task failure events

Details

Impact

Under specific template and failure conditions, an authenticated user may be able to retrieve sensitive values from Scaffolder task events. This can expose backend-managed credentials used during task execution.

Patches

Patched in @backstage/plugin-scaffolder-backend version 4.1.0

Workarounds

  • Restrict Scaffolder template execution and task-event access to trusted users until the patched version is deployed.

Timeline

Published
2 hours ago
October 07, 2026 at 04:24 PM UTC
Fixed (4.1.0)
1 month ago
August 28, 2026 at 08:20 AM UTC
Last Modified
2 hours ago
October 07, 2026 at 04:30 PM UTC