CVE-2026-106459High· 8.5▾ TwilightBackstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to contact unintended destinations and disclose Sentry integration credentials. Subsequent impact depends on network reachability and the privileges granted to the configured token. This issue is fixed in version 0.3.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106455High· 7.7Backstage is an open framework for building developer portals
CVE-2026-106501Critical· 9.6Backstage is an open framework for building developer portals
CVE-2026-106498High· 7.7Backstage is an open framework for building developer portals
CVE-2026-106458Medium· 6.5Backstage is an open framework for building developer portals
CVE-2026-106456Medium· 4.8Backstage is an open framework for building developer portals
CVE-2026-106457Medium· 6.8Backstage is an open framework for building developer portals