Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value. This issue is fixed in version 4.1.0. | |
| Title | Backstage: Sensitive information exposure in scaffolder task logs | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T21:40:15.510Z
Reserved: 2026-10-06T18:46:47.766Z
Link: CVE-2026-106504
No data.
Status : Received
Published: 2026-10-06T22:17:05.680
Modified: 2026-10-06T22:17:05.680
Link: CVE-2026-106504
No data.
OpenCVE Enrichment
No data.
-
CWE-532
Insertion of Sensitive Information into Log File