CVE-2026-106500 — Backstage is an open framework for building developer portals.
Description
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific timing and deployment conditions, affect files accessible to the Backstage backend. If backend application files are writable, the confidentiality, integrity, and availability of the backend may be compromised. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Changed
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
Affected
- Vendor
- npm
- Product
- @backstage/plugin-scaffolder-backend
Versions
- pkg:npm/%40backstage/plugin-scaffolder-backend < 4.1.0
Stated as the source expressed them.
References
- otherOSV webhttps://github.com/backstage/backstage/commit/0d24f1b8701f3dde6cd597f81997c1ea873a43ae
- otherOSV webhttps://github.com/backstage/backstage/commit/56be299dd3ef6706e13e76ea2f8a9b0dd0b6413d
- otherOSV webhttps://github.com/backstage/backstage/commit/9e86c95a1a3ddfd54db03731cd8678aa63495175
- otherOSV webhttps://github.com/backstage/backstage/releases/tag/v1.49.6
- otherOSV webhttps://github.com/backstage/backstage/releases/tag/v1.50.5
- otherOSV webhttps://github.com/backstage/backstage/releases/tag/v1.54.6
- otherOSV webhttps://github.com/backstage/backstage/security/advisories/GHSA-xvgh-hmx8-9xxf
- advisoryOSV GHSA-xvgh-hmx8-9xxfhttps://osv.dev/vulnerability/GHSA-xvgh-hmx8-9xxf
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-106500
- vendorOSV packagehttps://github.com/backstage/backstage
Related threats
same CWE or vendorCVE-2026-84271 — IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer.
CVE-2026-84271 · 2h ago
CVE-2026-107707 — Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged user…
CVE-2026-107707 · 2h ago
CVE-2026-107608 — Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent…
CVE-2026-107608 · 2h ago
CVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107392 · 2h ago
CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107391 · 2h ago
CVE-2026-107389 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107389 · 2h ago