CVE-2026-106560

high

Description

Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process. This issue is fixed in version 0.3.25.

References

https://github.com/backstage/backstage/security/advisories/GHSA-2cmg-v53w-8xfp

https://github.com/backstage/backstage/releases/tag/v1.54.6

https://github.com/backstage/backstage/commit/5f0000c1d0af05571e357926b3fa33a453337ff0

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94373

Details

Source: Mitre, NVD

Published: 2026-10-07

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:P

Severity: High

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Severity: High

EPSS

EPSS: 0.00329