---
id: CVE-2026-106459
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. From 0.3.0
  until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is
  affected by improper input validation in sentry scaffolder actions. An
  authenticated…
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-200
  - CWE-918
vendor: backstage
product: backstage
affected:
  - 'backstage >= 1.47.0, < 1.54.8'
  - 'plugin-scaffolder-backend-module-sentry >= 0.3.0, < 0.3.8'
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:16.450'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106459'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/b0170fad7962fb8c3d71366b5265cf283c7bbcf7
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.54.8'
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.55.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-g734-fhp4-7mfp
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T21:20:28.981Z'
---

## Overview

Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to contact unintended destinations and disclose Sentry integration credentials. Subsequent impact depends on network reachability and the privileges granted to the configured token. This issue is fixed in version 0.3.8.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
