Skip to content
Threat Feed
high advisory

Improper Input Validation in Backstage Sentry Scaffolder Module

An authenticated internal user can exploit improper input validation in the Backstage Sentry scaffolder module to trigger SSRF and disclose sensitive integration credentials.

CVE search metadata

CVE search record: CVE-2026-106459. Severity: high. CVSS: 8.5. KEV: no. Product: @backstage/plugin-scaffolder-backend-module-sentry (>= 0.3.0, < 0.3.8). Brief: Improper Input Validation in Backstage Sentry Scaffolder Module. Brief link: https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/

The @backstage/plugin-scaffolder-backend-module-sentry package (versions 0.3.0 through 0.3.7) contains an improper input validation vulnerability, tracked as CVE-2026-106459. This vulnerability allows an authenticated user with permission to execute scaffolder actions to manipulate the apiBaseUrl parameter. By supplying a malicious URL, an attacker can force the Backstage backend server to perform unauthorized outbound HTTP requests. This Server-Side Request Forgery (SSRF) primitive enables the attacker to interact with internal infrastructure or reach unintended external destinations. Crucially, the exploitation of this flaw can result in the disclosure of Sentry integration credentials configured within the Backstage environment. Defenders should upgrade to version 0.3.8 or later and migrate custom apiBaseUrl configurations to the global scaffolder.sentry.apiBaseUrl setting.

Impact

Successful exploitation allows an authenticated internal user to abuse the Sentry scaffolder action to conduct SSRF attacks. This leads to the potential exfiltration of sensitive integration credentials and provides a foothold to pivot into internal network segments reachable by the Backstage backend service. The severity is high as it facilitates unauthorized credential access and lateral movement potential within the internal development environment.

Recommendation

  • Upgrade the @backstage/plugin-scaffolder-backend-module-sentry package to version 0.3.8 or later.
  • Apply the configuration change by moving any custom apiBaseUrl values from action-level definitions to the scaffolder.sentry.apiBaseUrl global setting.
  • Restrict the scaffolder.action.execute permission for Sentry-related actions to a strictly controlled list of trusted users and templates until patching is complete.
  • Disable the vulnerable Sentry scaffolder actions as a temporary workaround if immediate patching is not possible.

Immediate actions

Upgrade @backstage/plugin-scaffolder-backend-module-sentry to version 0.3.8 or later

DevOps 48h

Mitigations

Restrict scaffolder.action.execute permissions for Sentry actions to trusted entities

immediate AppSec

CVE-2026-106459