Improper Input Validation in Backstage Sentry Scaffolder Module
An authenticated internal user can exploit improper input validation in the Backstage Sentry scaffolder module to trigger SSRF and disclose sensitive integration credentials.
CVE search metadata
CVE search record: CVE-2026-106459. Severity: high. CVSS: 8.5. KEV: no. Product: @backstage/plugin-scaffolder-backend-module-sentry (>= 0.3.0, < 0.3.8). Brief: Improper Input Validation in Backstage Sentry Scaffolder Module. Brief link: https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/
The @backstage/plugin-scaffolder-backend-module-sentry package (versions 0.3.0 through 0.3.7) contains an improper input validation vulnerability, tracked as CVE-2026-106459. This vulnerability allows an authenticated user with permission to execute scaffolder actions to manipulate the apiBaseUrl parameter. By supplying a malicious URL, an attacker can force the Backstage backend server to perform unauthorized outbound HTTP requests. This Server-Side Request Forgery (SSRF) primitive enables the attacker to interact with internal infrastructure or reach unintended external destinations. Crucially, the exploitation of this flaw can result in the disclosure of Sentry integration credentials configured within the Backstage environment. Defenders should upgrade to version 0.3.8 or later and migrate custom apiBaseUrl configurations to the global scaffolder.sentry.apiBaseUrl setting.
Impact
Successful exploitation allows an authenticated internal user to abuse the Sentry scaffolder action to conduct SSRF attacks. This leads to the potential exfiltration of sensitive integration credentials and provides a foothold to pivot into internal network segments reachable by the Backstage backend service. The severity is high as it facilitates unauthorized credential access and lateral movement potential within the internal development environment.
Recommendation
- Upgrade the
@backstage/plugin-scaffolder-backend-module-sentrypackage to version 0.3.8 or later. - Apply the configuration change by moving any custom
apiBaseUrlvalues from action-level definitions to thescaffolder.sentry.apiBaseUrlglobal setting. - Restrict the
scaffolder.action.executepermission for Sentry-related actions to a strictly controlled list of trusted users and templates until patching is complete. - Disable the vulnerable Sentry scaffolder actions as a temporary workaround if immediate patching is not possible.
Immediate actions
Upgrade @backstage/plugin-scaffolder-backend-module-sentry to version 0.3.8 or later
Mitigations
Restrict scaffolder.action.execute permissions for Sentry actions to trusted entities
CVE-2026-106459