Backstage: Improper input validation in scaffolder task list ordering
Summary
| CVE | CVE-2026-106506 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 22:17:05 UTC |
| Updated | 2026-10-06 22:17:05 UTC |
| Description | Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-202 | CWE-203 | CWE-202 CWE-202: Exposure of Sensitive Information Through Data Queries | CWE-203 CWE-203: Observable Discrepancy
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Backstage | Backstage | affected < 1.54.6 | Not specified |
| CNA | @backstage | Plugin-scaffolder-backend | affected < 4.1.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/backstage/backstage/commit/e673a869449874a9169e8f89852e75e862... | [email protected] | github.com | |
| github.com/backstage/backstage/security/advisories/GHSA-vwp5-f99x-x3rq | [email protected] | github.com | |
| github.com/backstage/backstage/releases/tag/v1.54.6 | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.