Skip to content
Threat Feed
high advisory

Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules

Authenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.

CVE search metadata

CVE search record: CVE-2026-106486. Severity: high. CVSS: 8.5. KEV: no. Product: plugin-scaffolder-backend-module-bitbucket-cloud (< 0.3.10), plugin-scaffolder-backend-module-bitbucket-server (< 0.2.25). Brief: Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules. Brief link: https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/

The Backstage Scaffolder backend modules for Bitbucket Cloud and Bitbucket Server contain an improper filesystem validation vulnerability, tracked as CVE-2026-106486. This flaw exists within the scaffolder actions responsible for interacting with Bitbucket repositories. An authenticated user who has the privileges to execute templates and the ability to influence the targeted Bitbucket repository parameter can supply malicious input to traverse the filesystem on the backend host. By manipulating these inputs, an attacker may escape the expected working directory, potentially reading sensitive configuration files, modifying application code, or deleting arbitrary files. This vulnerability poses a significant risk to backend integrity and confidentiality, particularly in environments where untrusted users have template creation or execution access.

Impact

Successful exploitation allows an authenticated attacker to perform unauthorized file operations on the host running the Backstage backend. This can result in the compromise of backend confidentiality (sensitive file exfiltration), integrity (malicious code injection), or availability (system file deletion). The scope of impact is limited by the permissions of the process running the Backstage backend service.

Recommendation

  • Upgrade @backstage/plugin-scaffolder-backend-module-bitbucket-cloud to version 0.3.10 or later.
  • Upgrade @backstage/plugin-scaffolder-backend-module-bitbucket-server to version 0.2.25 or later.
  • Apply administrative restrictions on Scaffolder template execution, limiting them to trusted users only.
  • Audit existing Scaffolder templates to identify and restrict actions that accept user-controlled target repository inputs until patching is complete.

Immediate actions

Upgrade affected Backstage modules to patched versions

IT Operations 48h

Mitigations

Restrict template execution to trusted users and sanitize repository parameters

immediate DevOps

CVE-2026-106486