@backstage/plugin-scaffolder-backend
npm7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @backstage/plugin-scaffolder-backendpage 1 of 1
- CVE-2021-41151MEDIUMCVSS 6.8EG 6.8✓ Fixed in 0.15.92021-10-18
Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitive files from the environment where Scaffolder Tasks are run. The attack is executed by crafting a custom Scaffolder tem…
- CVE-2021-43783HIGHCVSS 8.5EG 8.5✓ Fixed in 0.15.142021-11-29
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the template in a way that…
- CVE-2023-35926HIGHCVSS 8.0EG 8.0✓ Fixed in 1.15.02023-06-22
Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this sandbox so far has …
- CVE-2025-55285LOWCVSS 2.6EG 2.6✓ Fixed in 2.1.12025-08-15
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets w…
- CVE-2026-24046HIGHCVSS 7.1EG 7.1✓ Fixed in 3.1.12026-01-21
Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder t…
- CVE-2026-29184LOWCVSS 2.0EG 2.0✓ Fixed in 3.1.42026-03-07
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been p…
- CVE-2026-32237MEDIUMCVSS 4.4EG 4.4✓ Fixed in 3.1.52026-03-12
Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Se…
Check whether @backstage/plugin-scaffolder-backend is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @backstage/plugin-scaffolder-backend CVEs against the assets you own.
Start Free Scan →