CVE-2026-106486 — Backstage is an open framework for building developer portals.
Description
Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect paths outside the expected working area, potentially compromising backend confidentiality, integrity, or availability. This issue is fixed in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud 0.3.10 and @backstage/plugin-scaffolder-backend-module-bitbucket-server 0.2.25.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Changed
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
Affected
- Vendor
- npm
- Product
- @backstage/plugin-scaffolder-backend-module-bitbucket-cloud
Versions
- pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-cloud < 0.3.10
- pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-server < 0.2.25
Stated as the source expressed them.
References
- otherOSV webhttps://github.com/backstage/backstage/commit/818528e112c36167d76187e9e63fb518399c4dd2
- otherOSV webhttps://github.com/backstage/backstage/releases/tag/v1.54.6
- otherOSV webhttps://github.com/backstage/backstage/security/advisories/GHSA-g8rx-f7m5-7794
- advisoryOSV GHSA-g8rx-f7m5-7794https://osv.dev/vulnerability/GHSA-g8rx-f7m5-7794
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-106486
- vendorOSV packagehttps://github.com/backstage/backstage
Related threats
same CWE or vendorCVE-2026-84275 — IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality.
CVE-2026-84275 · 2h ago
CVE-2026-107707 — Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged user…
CVE-2026-107707 · 2h ago
CVE-2026-107608 — Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent…
CVE-2026-107608 · 2h ago
CVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107392 · 2h ago
CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107391 · 2h ago
CVE-2026-107389 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107389 · 2h ago