GHSA-8qp7-fhr9-fw53
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
Quick fix
GHSA-8qp7-fhr9-fw53 — @backstage/plugin-scaffolder-backend: upgrade to the fixed version with the command below.
npm install @backstage/plugin-scaffolder-backend@3.1.4Details
### Impact
A malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs.
The attack requires: - The ability to register a template in the catalog - A victim who executes the malicious template
### Patches Patched in `@backstage/plugin-scaffolder-backend` version 3.1.4
### Workarounds - Implement a custom permission policy that restricts scaffolder.task.read so users can only read their own task logs - Restrict who can register templates in the catalog to trusted users only
### Resources - Backstage Scaffolder permissions documentation: https://backstage.io/docs/permissions/plugin-authors/01-setup/ - Backstage Threat Model: https://backstage.io/docs/overview/threat-model/
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 3.1.4npm install @backstage/plugin-scaffolder-backend@3.1.4References
- https://github.com/backstage/backstage/security/advisories/GHSA-8qp7-fhr9-fw53[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-29184[ADVISORY]
- https://backstage.io/docs/overview/threat-model[WEB]
- https://backstage.io/docs/permissions/plugin-authors/01-setup[WEB]
- https://github.com/backstage/backstage[PACKAGE]