---
id: CVE-2026-106560
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. Prior to
  0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown
  package is affected by improper repository path validation in a scaffolder
  backend mod…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-22
vendor: backstage
product: '@backstage/plugin-scaffolder-backend-module-confluence-to-markdown'
affected:
  - '@backstage/plugin-scaffolder-backend-module-confluence-to-markdown < 0.3.25'
patched:
  - '@backstage/plugin-scaffolder-backend-module-confluence-to-markdown 0.3.25'
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:17.120'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106560'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/5f0000c1d0af05571e357926b3fa33a453337ff0
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.54.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-2cmg-v53w-8xfp
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106560'
  - url: 'https://github.com/advisories/GHSA-2cmg-v53w-8xfp'
tags:
  - nvd
  - ghsa
  - npm
  - cve.org
aliases:
  - GHSA-2cmg-v53w-8xfp
ecosystem: npm
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T17:11:06.307755Z'
ingestedAt: '2026-10-07T15:36:04.053Z'
---

## Overview

Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process. This issue is fixed in version 0.3.25.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-106560)

Affected packages:

- `@backstage/plugin-scaffolder-backend-module-confluence-to-markdown < 0.3.25`

Patched in:

- `@backstage/plugin-scaffolder-backend-module-confluence-to-markdown 0.3.25`

Source: https://github.com/advisories/GHSA-2cmg-v53w-8xfp
