Vulnerability GHSA-rq6q-wr2q-7pgp
High Risk
HIGH RISK
CVSS Score: 7.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 months ago
January 21, 2026 at 10:36 PM UTC
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
0.0.0-nightly-20220811024336 - 0.12.1 and 0.13.0 - 0.13.1 and 0.14.0 - 0.14.1-next.1
0.0.0-nightly-20220811024336 - 0.12.1 and 0.13.0 - 0.13.1 and 0.14.0 - 0.14.1-next.1
Summary
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
Details
Impact
Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:
- Read arbitrary files via the
debug:logaction by creating a symlink pointing to sensitive files (e.g.,/etc/passwd, configuration files, secrets) - Delete arbitrary files via the
fs:deleteaction by creating symlinks pointing outside the workspace - Write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks
This affects any Backstage deployment where users can create or execute Scaffolder templates.
Patches
This vulnerability is fixed in the following package versions:
@backstage/backend-defaultsversion 0.12.2, 0.13.2, 0.14.1, 0.15.0@backstage/plugin-scaffolder-backendversion 2.2.2, 3.0.2, 3.1.1@backstage/plugin-scaffolder-nodeversion 0.11.2, 0.12.3
Users should upgrade to these versions or later.
Workarounds
- Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates
- Restrict who can create and execute Scaffolder templates using the permissions framework
- Audit existing templates for symlink usage
- Run Backstage in a containerized environment with limited filesystem access
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 hours ago
Backstage: Improper input validation in cloud storage URL readers
0.0.0-nightly-20220811024336 - 0.17.7 GHSA-7649-wm97-w3j3
0.0.0-nightly-20220811024336 - 0.17.7 GHSA-7649-wm97-w3j3
Medium Risk
3 hours ago
Backstage: Incorrect authorization in scaffolder task listing
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-7hfw-grcm-cqm6
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-7hfw-grcm-cqm6
Medium Risk
5 hours ago
Backstage may expose sensitive information in Scaffolder task failure events
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-95p4-vv4g-jxxm
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-95p4-vv4g-jxxm
Medium Risk
5 hours ago
Backstage has sensitive information exposure in scaffolder task logs
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-4xvq-3m68-h444
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-4xvq-3m68-h444
Medium Risk
5 hours ago
Backstage has improper input validation in scaffolder task list ordering
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-vwp5-f99x-x3rq
0.0.0-nightly-202010102951 - 4.1.0-next.0 GHSA-vwp5-f99x-x3rq
Impacted packages
Timeline
Published
8 months ago
January 21, 2026 at 10:36 PM UTC
Fixed (3.1.1)
8 months ago
January 20, 2026 at 08:00 PM UTC
Fixed (0.12.3)
8 months ago
January 20, 2026 at 08:02 PM UTC
Fixed (0.14.1)
8 months ago
January 21, 2026 at 01:29 PM UTC
Fixed (0.13.2)
8 months ago
January 21, 2026 at 01:34 PM UTC
Fixed (3.0.2)
8 months ago
January 21, 2026 at 01:36 PM UTC
Fixed (0.12.2)
8 months ago
January 21, 2026 at 01:46 PM UTC
Fixed (2.2.2)
8 months ago
January 21, 2026 at 01:48 PM UTC
Fixed (0.11.2)
8 months ago
January 21, 2026 at 01:48 PM UTC
Last Modified
8 months ago
February 03, 2026 at 03:12 AM UTC