---
id: CVE-2026-106506
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. Prior to 4.1.0,
  the @backstage/plugin-scaffolder-backend package is affected by improper input
  validation in scaffolder task list ordering. An authenticated Backstage user
  wi…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-202
  - CWE-203
vendor: backstage
product: '@backstage/plugin-scaffolder-backend'
affected:
  - '@backstage/plugin-scaffolder-backend < 4.1.0'
patched:
  - '@backstage/plugin-scaffolder-backend 4.1.0'
published: '2026-10-06'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:16:49.977'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106506'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/e673a869449874a9169e8f89852e75e862011b93
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.54.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-vwp5-f99x-x3rq
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106506'
  - url: 'https://github.com/advisories/GHSA-vwp5-f99x-x3rq'
tags:
  - nvd
  - ghsa
  - npm
  - cve.org
aliases:
  - GHSA-vwp5-f99x-x3rq
ecosystem: npm
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T15:27:07.462310Z'
epss: 0.00217
epssPercentile: 0.11159
ingestedAt: '2026-10-06T22:23:15.968Z'
---

## Overview

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-106506)

Affected packages:

- `@backstage/plugin-scaffolder-backend < 4.1.0`

Patched in:

- `@backstage/plugin-scaffolder-backend 4.1.0`

Source: https://github.com/advisories/GHSA-vwp5-f99x-x3rq
