{"id":"GHSA-rq6q-wr2q-7pgp","summary":"Backstage has a Possible Symlink Path Traversal in Scaffolder Actions","details":"### Impact\n\nMultiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:\n\n1. **Read arbitrary files** via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets)\n2. **Delete arbitrary files** via the `fs:delete` action by creating symlinks pointing outside the workspace\n3. **Write files outside the workspace** via archive extraction (tar/zip) containing malicious symlinks\n\nThis affects any Backstage deployment where users can create or execute Scaffolder templates.\n\n### Patches\n\nThis vulnerability is fixed in the following package versions:\n\n- `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, 0.15.0\n- `@backstage/plugin-scaffolder-backend` version 2.2.2, 3.0.2, 3.1.1\n- `@backstage/plugin-scaffolder-node` version 0.11.2, 0.12.3\n\nUsers should upgrade to these versions or later.\n\n### Workarounds\n\n- Follow the recommendation in the [Backstage Threat Model](https://backstage.io/docs/overview/threat-model#scaffolder) to limit access to creating and updating templates\n- Restrict who can create and execute Scaffolder templates using the permissions framework\n- Audit existing templates for symlink usage\n- Run Backstage in a containerized environment with limited filesystem access\n\n### References\n\n- [CWE-59: Improper Link Resolution Before File Access](https://cwe.mitre.org/data/definitions/59.html)\n- [OWASP Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal)","aliases":["CVE-2026-24046"],"modified":"2026-02-03T03:12:21.539851Z","published":"2026-01-21T22:36:36Z","database_specific":{"cwe_ids":["CWE-22","CWE-59"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-01-21T22:36:36Z","nvd_published_at":"2026-01-21T23:15:53Z"},"references":[{"type":"WEB","url":"https://github.com/backstage/backstage/security/advisories/GHSA-rq6q-wr2q-7pgp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24046"},{"type":"WEB","url":"https://github.com/backstage/backstage/commit/c641c147ab371a9a8a2f5f67fdb7cb9c97ef345d"},{"type":"PACKAGE","url":"https://github.com/backstage/backstage"}],"affected":[{"package":{"name":"@backstage/backend-defaults","ecosystem":"npm","purl":"pkg:npm/%40backstage/backend-defaults"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"}},{"package":{"name":"@backstage/backend-defaults","ecosystem":"npm","purl":"pkg:npm/%40backstage/backend-defaults"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.13.0"},{"fixed":"0.13.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"}},{"package":{"name":"@backstage/backend-defaults","ecosystem":"npm","purl":"pkg:npm/%40backstage/backend-defaults"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.14.0"},{"fixed":"0.14.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"}},{"package":{"name":"@backstage/plugin-scaffolder-backend","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-scaffolder-backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"}},{"package":{"name":"@backstage/plugin-scaffolder-backend","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-scaffolder-backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"}},{"package":{"name":"@backstage/plugin-scaffolder-backend","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-scaffolder-backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.1.0"},{"fixed":"3.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"}},{"package":{"name":"@backstage/plugin-scaffolder-node","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-scaffolder-node"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.11.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"}},{"package":{"name":"@backstage/plugin-scaffolder-node","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-scaffolder-node"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.12.0"},{"fixed":"0.12.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rq6q-wr2q-7pgp/GHSA-rq6q-wr2q-7pgp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L"}]}