VDB
Sign up
HIGH7.1

GHSA-rq6q-wr2q-7pgp

Backstage has a Possible Symlink Path Traversal in Scaffolder Actions

Quick fix

GHSA-rq6q-wr2q-7pgp — @backstage/backend-defaults: upgrade to the fixed version with the command below.

npm install @backstage/backend-defaults@0.12.2

Details

### Impact

Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:

1. **Read arbitrary files** via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets) 2. **Delete arbitrary files** via the `fs:delete` action by creating symlinks pointing outside the workspace 3. **Write files outside the workspace** via archive extraction (tar/zip) containing malicious symlinks

This affects any Backstage deployment where users can create or execute Scaffolder templates.

### Patches

This vulnerability is fixed in the following package versions:

- `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, 0.15.0 - `@backstage/plugin-scaffolder-backend` version 2.2.2, 3.0.2, 3.1.1 - `@backstage/plugin-scaffolder-node` version 0.11.2, 0.12.3

Users should upgrade to these versions or later.

### Workarounds

- Follow the recommendation in the [Backstage Threat Model](https://backstage.io/docs/overview/threat-model#scaffolder) to limit access to creating and updating templates - Restrict who can create and execute Scaffolder templates using the permissions framework - Audit existing templates for symlink usage - Run Backstage in a containerized environment with limited filesystem access

### References

- [CWE-59: Improper Link Resolution Before File Access](https://cwe.mitre.org/data/definitions/59.html) - [OWASP Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@backstage/backend-defaults
Introduced in: 0Fixed in: 0.12.2
Fixnpm install @backstage/backend-defaults@0.12.2
npm/@backstage/backend-defaults
Introduced in: 0.13.0Fixed in: 0.13.2
Fixnpm install @backstage/backend-defaults@0.13.2
npm/@backstage/backend-defaults
Introduced in: 0.14.0Fixed in: 0.14.1
Fixnpm install @backstage/backend-defaults@0.14.1
npm/@backstage/plugin-scaffolder-backend
Introduced in: 0Fixed in: 2.2.2
Fixnpm install @backstage/plugin-scaffolder-backend@2.2.2
npm/@backstage/plugin-scaffolder-backend
Introduced in: 3.0.0Fixed in: 3.0.2
Fixnpm install @backstage/plugin-scaffolder-backend@3.0.2
npm/@backstage/plugin-scaffolder-backend
Introduced in: 3.1.0Fixed in: 3.1.1
Fixnpm install @backstage/plugin-scaffolder-backend@3.1.1
npm/@backstage/plugin-scaffolder-node
Introduced in: 0Fixed in: 0.11.2
Fixnpm install @backstage/plugin-scaffolder-node@0.11.2
npm/@backstage/plugin-scaffolder-node
Introduced in: 0.12.0Fixed in: 0.12.3
Fixnpm install @backstage/plugin-scaffolder-node@0.12.3

References