CVE-2026-106500: @backstage Plugin-Scaffolder-Backend

High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific timing and deployment conditions, affect files accessible to the Backstage backend. If backend application files are writable, the confidentiality, integrity, and availability of the backend may be compromised. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.

Affected products

  • @backstage Plugin-Scaffolder-Backend: before 3.3.1 (fixed in 3.3.1); from 3.4.0, before 3.4.1 (fixed in 3.4.1); from 4.0.0, before 4.0.3 (fixed in 4.0.3); from 4.0.4, before 4.1.0 (fixed in 4.1.0)
  • Backstage Backstage: before 1.49.6 (fixed in 1.49.6); from 1.50.0-next.0, before 1.50.5 (fixed in 1.50.5); from 1.51.0-next.0, before 1.54.6 (fixed in 1.54.6)

Published 2026-10-06. Last modified 2026-10-07.