CVE-2026-106499
@backstage/plugin-scaffolder-backend: Insertion of Sensitive Information into Log File (CVE-2026-106499)
Description
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder templates are affected. A template author could cause secret-derived values used during template iteration to be persisted and exposed to users who can access the resulting task logs. This issue is fixed in version 4.1.0.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
Metrics
Show all metrics
Weakness classes (CWE)
CWE-532Base
Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
cwe.mitre.org →
References & sources
- https://github.com/backstage/backstage/security/advisories/GHSA-mfvq-x7vr-rgqgx_refsource_CONFIRM
- https://github.com/backstage/backstage/commit/dc30fae2d96cb1606d36cc40b242f9b9e539bd70x_refsource_MISC
- https://github.com/backstage/backstage/releases/tag/v1.54.6x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-106499advisory
- https://github.com/backstage/backstagepackage
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-07 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-106499","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
- New CVE Received2026-10-06 22:17 UTC· security-advisories@github.com
- Description: Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder templates are affected. A template author could cause secret-derived values used during template iteration to be persisted and exposed to users who can access the resulting task logs. This issue is fixed in version 4.1.0.
- CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- CWE: CWE-532
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/106xxx/CVE-2026-106499.json">CVE-2026-106499</a>