Backstage Scaffolder Flaw Lets Users Read Other Users' Task Execution Data, Including Credentials
What happened
GitHub Security Advisory GHSA-g2v8-7jhw-pp8p discloses a sensitive information exposure vulnerability in Backstage's @backstage/plugin-scaffolder-backend, tracked as CVE-2026-106501 with a CVSS score of 9.6. According to the advisory, an authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data from that task. In deployments where that execution data includes credentials for an external service, this could permit disclosure of those credentials and unauthorized changes to the external service. A public PoC is reported to exist. The issue is patched in version 4.1.0 of the plugin.
Why it matters
Backstage's Scaffolder is widely used for self-service scaffolding of new software components, and task runs frequently touch external systems (cloud providers, CI/CD, source control, secrets managers) to provision resources. If any authenticated user — not just task owners or admins — can read another user's task output, any secrets or tokens surfaced during that execution are effectively exposed platform-wide. Because Backstage is typically an internal developer-platform with broad employee access, the practical blast radius can be large: a low-privilege insider or a compromised low-privilege account could potentially pivot into higher-value external integrations.
What defenders should do now
- Identify whether your Backstage instance runs
@backstage/plugin-scaffolder-backendbelow4.1.0and prioritize upgrading. - Until patched, apply the advisory's documented workaround: configure the
scaffolder.task.readpermission with theisTaskOwnercondition so users can only read tasks they themselves created. - Restrict scaffolder templates/integrations that embed credentials in task execution output to trusted operators only, until upgraded.
- Review Scaffolder task access logs (where available) for cross-user task reads that predate any policy change — this would be the indicator that exposure already occurred.
- Treat any credentials that may have appeared in Scaffolder task logs as potentially exposed and consider rotation, especially for integrations used by templates accessible to a broad user base.
Developing intel
This is a same-day advisory and df00tech has not independently verified exploitation in the wild beyond the reported public PoC. Details may be refined as the Backstage maintainers or researchers publish further analysis. See the original GitHub Security Advisory for authoritative details: GHSA-g2v8-7jhw-pp8p.