Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0.

Project Subscriptions

Vendors Products
Backstage Subscribe
Backstage Subscribe
Plugin-scaffolder-backend Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Backstage
Backstage backstage
Backstage plugin-scaffolder-backend
Vendors & Products Backstage
Backstage backstage
Backstage plugin-scaffolder-backend

Tue, 06 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0.
Title Backstage: Improper input validation in scaffolder task list ordering
Weaknesses CWE-202
CWE-203
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T21:44:31.904Z

Reserved: 2026-10-06T18:46:47.766Z

Link: CVE-2026-106506

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T22:17:05.993

Modified: 2026-10-06T22:17:05.993

Link: CVE-2026-106506

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T04:30:11Z

Weaknesses