Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules
Authenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.
CVE search metadata
CVE search record: CVE-2026-106486. Severity: high. CVSS: 8.5. KEV: no. Product: plugin-scaffolder-backend-module-bitbucket-cloud (< 0.3.10), plugin-scaffolder-backend-module-bitbucket-server (< 0.2.25). Brief: Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules. Brief link: https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/
The Backstage Scaffolder backend modules for Bitbucket Cloud and Bitbucket Server contain an improper filesystem validation vulnerability, tracked as CVE-2026-106486. This flaw exists within the scaffolder actions responsible for interacting with Bitbucket repositories. An authenticated user who has the privileges to execute templates and the ability to influence the targeted Bitbucket repository parameter can supply malicious input to traverse the filesystem on the backend host. By manipulating these inputs, an attacker may escape the expected working directory, potentially reading sensitive configuration files, modifying application code, or deleting arbitrary files. This vulnerability poses a significant risk to backend integrity and confidentiality, particularly in environments where untrusted users have template creation or execution access.
Impact
Successful exploitation allows an authenticated attacker to perform unauthorized file operations on the host running the Backstage backend. This can result in the compromise of backend confidentiality (sensitive file exfiltration), integrity (malicious code injection), or availability (system file deletion). The scope of impact is limited by the permissions of the process running the Backstage backend service.
Recommendation
- Upgrade
@backstage/plugin-scaffolder-backend-module-bitbucket-cloudto version 0.3.10 or later. - Upgrade
@backstage/plugin-scaffolder-backend-module-bitbucket-serverto version 0.2.25 or later. - Apply administrative restrictions on Scaffolder template execution, limiting them to trusted users only.
- Audit existing Scaffolder templates to identify and restrict actions that accept user-controlled target repository inputs until patching is complete.
Immediate actions
Upgrade affected Backstage modules to patched versions
Mitigations
Restrict template execution to trusted users and sanitize repository parameters
CVE-2026-106486