Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @backstage/plugin-scaffolder-backend-module-gitlab
  4. ›
  5. CVE-2026-106462

CVE-2026-106462: Backstage's scaffolder credential handling may allow unintended GitHub authentication fallback

October 7, 2026

Scaffolder actions that interact with source control systems may not consistently enforce the intended credential boundaries under certain configurations. An authenticated user could perform operations with broader access than intended.

References

  • github.com/advisories/GHSA-29gx-h2m3-xw44
  • github.com/backstage/backstage/commit/6fb2a41ea47da37eafe5ea744050
  • github.com/backstage/backstage/commit/6fb2a41ea47da37eafe5ea744050ef90be6820c0
  • github.com/backstage/backstage/releases/tag/v1.54.6
  • github.com/backstage/backstage/security/advisories/GHSA-29gx-h2m3-xw44
  • nvd.nist.gov/vuln/detail/CVE-2026-106462

Code Behaviors & Features

Detect and mitigate CVE-2026-106462 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.11.10

Fixed versions

  • 0.11.10

Solution

Upgrade to version 0.11.10 or above.

Impact 6.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')
  • CWE-863: Incorrect Authorization

Source file

npm/@backstage/plugin-scaffolder-backend-module-gitlab/CVE-2026-106462.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 11 Oct 2026 00:19:06 +0000.