← Blog · · df00tech

Backstage Scaffolder Flaw Lets Users Read Other Users' Task Execution Data, Including Credentials

breaking ghsa npm CVE-2026-106501

What happened

GitHub Security Advisory GHSA-g2v8-7jhw-pp8p discloses a sensitive information exposure vulnerability in Backstage's @backstage/plugin-scaffolder-backend, tracked as CVE-2026-106501 with a CVSS score of 9.6. According to the advisory, an authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data from that task. In deployments where that execution data includes credentials for an external service, this could permit disclosure of those credentials and unauthorized changes to the external service. A public PoC is reported to exist. The issue is patched in version 4.1.0 of the plugin.

Why it matters

Backstage's Scaffolder is widely used for self-service scaffolding of new software components, and task runs frequently touch external systems (cloud providers, CI/CD, source control, secrets managers) to provision resources. If any authenticated user — not just task owners or admins — can read another user's task output, any secrets or tokens surfaced during that execution are effectively exposed platform-wide. Because Backstage is typically an internal developer-platform with broad employee access, the practical blast radius can be large: a low-privilege insider or a compromised low-privilege account could potentially pivot into higher-value external integrations.

What defenders should do now

  • Identify whether your Backstage instance runs @backstage/plugin-scaffolder-backend below 4.1.0 and prioritize upgrading.
  • Until patched, apply the advisory's documented workaround: configure the scaffolder.task.read permission with the isTaskOwner condition so users can only read tasks they themselves created.
  • Restrict scaffolder templates/integrations that embed credentials in task execution output to trusted operators only, until upgraded.
  • Review Scaffolder task access logs (where available) for cross-user task reads that predate any policy change — this would be the indicator that exposure already occurred.
  • Treat any credentials that may have appeared in Scaffolder task logs as potentially exposed and consider rotation, especially for integrations used by templates accessible to a broad user base.

Developing intel

This is a same-day advisory and df00tech has not independently verified exploitation in the wild beyond the reported public PoC. Details may be refined as the Backstage maintainers or researchers publish further analysis. See the original GitHub Security Advisory for authoritative details: GHSA-g2v8-7jhw-pp8p.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.