{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abackstagebackstage_plugin_scaffolder_backend_module_sentry/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:backstage_plugin_scaffolder_backend_module_sentry:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-106459"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@backstage/plugin-scaffolder-backend-module-sentry (\u003e= 0.3.0, \u003c 0.3.8)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eThe \u003ccode\u003e@backstage/plugin-scaffolder-backend-module-sentry\u003c/code\u003e package (versions 0.3.0 through 0.3.7) contains an improper input validation vulnerability, tracked as CVE-2026-106459. This vulnerability allows an authenticated user with permission to execute scaffolder actions to manipulate the \u003ccode\u003eapiBaseUrl\u003c/code\u003e parameter. By supplying a malicious URL, an attacker can force the Backstage backend server to perform unauthorized outbound HTTP requests. This Server-Side Request Forgery (SSRF) primitive enables the attacker to interact with internal infrastructure or reach unintended external destinations. Crucially, the exploitation of this flaw can result in the disclosure of Sentry integration credentials configured within the Backstage environment. Defenders should upgrade to version 0.3.8 or later and migrate custom \u003ccode\u003eapiBaseUrl\u003c/code\u003e configurations to the global \u003ccode\u003escaffolder.sentry.apiBaseUrl\u003c/code\u003e setting.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated internal user to abuse the Sentry scaffolder action to conduct SSRF attacks. This leads to the potential exfiltration of sensitive integration credentials and provides a foothold to pivot into internal network segments reachable by the Backstage backend service. The severity is high as it facilitates unauthorized credential access and lateral movement potential within the internal development environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@backstage/plugin-scaffolder-backend-module-sentry\u003c/code\u003e package to version 0.3.8 or later.\u003c/li\u003e\n\u003cli\u003eApply the configuration change by moving any custom \u003ccode\u003eapiBaseUrl\u003c/code\u003e values from action-level definitions to the \u003ccode\u003escaffolder.sentry.apiBaseUrl\u003c/code\u003e global setting.\u003c/li\u003e\n\u003cli\u003eRestrict the \u003ccode\u003escaffolder.action.execute\u003c/code\u003e permission for Sentry-related actions to a strictly controlled list of trusted users and templates until patching is complete.\u003c/li\u003e\n\u003cli\u003eDisable the vulnerable Sentry scaffolder actions as a temporary workaround if immediate patching is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:51:00Z","date_published":"2026-10-07T22:51:00Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/","summary":"An authenticated internal user can exploit improper input validation in the Backstage Sentry scaffolder module to trigger SSRF and disclose sensitive integration credentials.","title":"Improper Input Validation in Backstage Sentry Scaffolder Module","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:backstage:backstage_plugin_scaffolder_backend_module_sentry:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}