---
id: CVE-2026-106501
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. Prior to 3.3.1,
  3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is
  affected by sensitive information exposure in scaffolder. An authenticated
  Backsta…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-200
  - CWE-201
vendor: backstage
product: backstage
affected:
  - backstage < 1.49.6
  - 'backstage >= 1.50.0-next.0, < 1.50.5'
  - 'backstage >= 1.51.0-next.0, < 1.54.6'
  - plugin-scaffolder-backend < 3.3.1
  - 'plugin-scaffolder-backend >= 3.4.0, < 3.4.1'
  - 'plugin-scaffolder-backend >= 4.0.0, < 4.0.3'
  - 'plugin-scaffolder-backend >= 4.0.4, < 4.1.0'
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:17:05.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106501'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/66d2219edf0abe33ab7d0c1ced5d069d1e065be5
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/commit/c19838870476a8e29144c84b1a5ac0654ec20fb5
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/commit/e262d649981ff99bb01ca7077807ae3e25e85560
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.49.6'
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.50.5'
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.54.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-g2v8-7jhw-pp8p
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T22:23:15.967Z'
---

## Overview

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
