Description
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper input validation in confluence to markdown scaffolder module. Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content. This issue is fixed in version 0.3.25.
Published: 2026-10-07
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Arbitrary file write via template execution
Action: Apply patch
AI Analysis

Impact

Improper input validation in the Confluence-to-Markdown scaffolder module allows a user who can run scaffolder templates to influence where files are written during template execution. When attacker‑controlled Confluence content is processed, the module may write files to arbitrary paths, potentially overwriting system files or placing malicious content on the server. The consequence is unauthorized file manipulation, data loss, or platform compromise, depending on the files touched.

Affected Systems

All installations of Backstage that use the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package prior to version 0.3.25 are affected. This includes the Backstage framework itself, technically branded as Backstage. The specific module version vulnerability is mitigated starting with 0.3.25 and Backstage releases that incorporate that module version, such as v1.54.6.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a Backstage user with the ability to execute a template that processes attacker‑influenced Confluence content, suggesting that the attack vector is internal and depends on template‑execution permissions. Once triggered, the attacker can create or overwrite files at chosen paths, which could lead to code execution or data exfiltration if privileged files are affected.

Generated by OpenCVE AI on October 7, 2026 at 16:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @backstage/plugin-scaffolder-backend-module-confluence-to-markdown to version 0.3.25 or later, which contains the input‑validation fix.
  • Upgrade Backstage to at least v1.54.6, the release that bundles the fixed module version.
  • Restrict who can run scaffolder templates by enforcing role‑based access control and limiting template execution to trusted users only.

Generated by OpenCVE AI on October 7, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper input validation in confluence to markdown scaffolder module. Insufficient input validation in the Confluence to Markdown scaffolder module could allow an attacker to influence file write operations during template execution. Exploitation requires a Backstage user to run a template that processes attacker-influenced Confluence content. This issue is fixed in version 0.3.25.
Title Backstage: Improper input validation in Confluence to Markdown scaffolder module
Weaknesses CWE-22
CWE-73
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T16:16:19.815Z

Reserved: 2026-10-06T20:31:59.017Z

Link: CVE-2026-106559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T15:17:17.120

Modified: 2026-10-07T17:16:51.070

Link: CVE-2026-106559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T16:45:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path