CVE-2026-106499

@backstage/plugin-scaffolder-backend: Insertion of Sensitive Information into Log File (CVE-2026-106499)

mediumEPSS 0.3%

Description

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder templates are affected. A template author could cause secret-derived values used during template iteration to be persisted and exposed to users who can access the resulting task logs. This issue is fixed in version 4.1.0.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

npm@backstage/plugin-scaffolder-backend

Metrics

4.9
Source: cna-v3
17.5 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-07 17:59 UTC
CWE-532

Weakness classes (CWE)

  • CWE-532Base

    Insertion of Sensitive Information into Log File

    The product writes sensitive information to a log file.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-07 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-106499","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
  2. New CVE Received2026-10-06 22:17 UTC· security-advisories@github.com
    • Description: Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder templates are affected. A template author could cause secret-derived values used during template iteration to be persisted and exposed to users who can access the resulting task logs. This issue is fixed in version 4.1.0.
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
    • CWE: CWE-532
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/106xxx/CVE-2026-106499.json">CVE-2026-106499</a>