{"id":"GHSA-8wq8-6859-qx77","summary":"@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint","details":"### Impact                                                                                                                                                                         \n                                         \n  Authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly \n  redacted in log output but not in all parts of the response payload.\n                                                                                                                                                                                     \n  Deployments that have configured `scaffolder.defaultEnvironment.secrets` are affected.\n                          \n  ### Patches                            \n\n  This is patched in `@backstage/plugin-scaffolder-backend` version 3.1.5\n  ### Workarounds\n\n  Remove or empty the `scaffolder.defaultEnvironment.secrets` configuration from `app-config.yaml`. Alternatively, restrict access to the scaffolder dry-run functionality via the\n  permissions framework.\n\n  ### References\n\n  - [Backstage Scaffolder Backend documentation](https://backstage.io/docs/features/software-templates/)","aliases":["CVE-2026-32237"],"modified":"2026-03-14T01:56:22.133571Z","published":"2026-03-12T14:51:06Z","database_specific":{"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-12T14:51:06Z","nvd_published_at":"2026-03-12T19:16:19Z"},"references":[{"type":"WEB","url":"https://github.com/backstage/backstage/security/advisories/GHSA-8wq8-6859-qx77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32237"},{"type":"WEB","url":"https://github.com/backstage/backstage/commit/3b62dd2d6bf7623ebd23e4b5a6dceb209f98dfce"},{"type":"PACKAGE","url":"https://github.com/backstage/backstage"}],"affected":[{"package":{"name":"@backstage/plugin-scaffolder-backend","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-scaffolder-backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.1.0"},{"fixed":"3.1.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8wq8-6859-qx77/GHSA-8wq8-6859-qx77.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}