Impact
Improper input validation in the Confluence-to-Markdown scaffolder module allows a user who can run scaffolder templates to influence where files are written during template execution. When attacker‑controlled Confluence content is processed, the module may write files to arbitrary paths, potentially overwriting system files or placing malicious content on the server. The consequence is unauthorized file manipulation, data loss, or platform compromise, depending on the files touched.
Affected Systems
All installations of Backstage that use the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package prior to version 0.3.25 are affected. This includes the Backstage framework itself, technically branded as Backstage. The specific module version vulnerability is mitigated starting with 0.3.25 and Backstage releases that incorporate that module version, such as v1.54.6.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a Backstage user with the ability to execute a template that processes attacker‑influenced Confluence content, suggesting that the attack vector is internal and depends on template‑execution permissions. Once triggered, the attacker can create or overwrite files at chosen paths, which could lead to code execution or data exfiltration if privileged files are affected.
OpenCVE Enrichment