<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Backstage/Plugin-Scaffolder-Backend-Module-Sentry (&gt;= 0.3.0, &lt; 0.3.8) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@backstage/plugin-scaffolder-backend-module-sentry--0.3.0--0.3.8/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:51:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@backstage/plugin-scaffolder-backend-module-sentry--0.3.0--0.3.8/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Input Validation in Backstage Sentry Scaffolder Module</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/</link><pubDate>Wed, 07 Oct 2026 22:51:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-sentry-vulnerability/</guid><description>An authenticated internal user can exploit improper input validation in the Backstage Sentry scaffolder module to trigger SSRF and disclose sensitive integration credentials.</description><content:encoded><![CDATA[<p>The <code>@backstage/plugin-scaffolder-backend-module-sentry</code> package (versions 0.3.0 through 0.3.7) contains an improper input validation vulnerability, tracked as CVE-2026-106459. This vulnerability allows an authenticated user with permission to execute scaffolder actions to manipulate the <code>apiBaseUrl</code> parameter. By supplying a malicious URL, an attacker can force the Backstage backend server to perform unauthorized outbound HTTP requests. This Server-Side Request Forgery (SSRF) primitive enables the attacker to interact with internal infrastructure or reach unintended external destinations. Crucially, the exploitation of this flaw can result in the disclosure of Sentry integration credentials configured within the Backstage environment. Defenders should upgrade to version 0.3.8 or later and migrate custom <code>apiBaseUrl</code> configurations to the global <code>scaffolder.sentry.apiBaseUrl</code> setting.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated internal user to abuse the Sentry scaffolder action to conduct SSRF attacks. This leads to the potential exfiltration of sensitive integration credentials and provides a foothold to pivot into internal network segments reachable by the Backstage backend service. The severity is high as it facilitates unauthorized credential access and lateral movement potential within the internal development environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>@backstage/plugin-scaffolder-backend-module-sentry</code> package to version 0.3.8 or later.</li>
<li>Apply the configuration change by moving any custom <code>apiBaseUrl</code> values from action-level definitions to the <code>scaffolder.sentry.apiBaseUrl</code> global setting.</li>
<li>Restrict the <code>scaffolder.action.execute</code> permission for Sentry-related actions to a strictly controlled list of trusted users and templates until patching is complete.</li>
<li>Disable the vulnerable Sentry scaffolder actions as a temporary workaround if immediate patching is not possible.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>ssrf</category><category>supply-chain</category></item></channel></rss>