Disclosure summary
### Impact An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect filesystem paths outside the expected working area. Depending on the backend deployment, this could compromise backend confidentiality, integrity, or availability. ### Patches - `@backstage/plugin-scaffolder-backend-module-bitbucket-cloud` version `0.3.10` - `@backstage/plugin-scaffolder-backend-module-bitbucket-server` version `0.2.25` ### Workarounds - Restrict execution of affected Scaffolder templates to trusted users. - Avoid templates that accept user-controlled target repositories for these actions.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-g8rx-f7m5-7794
Open original source · Updated Oct 07, 2026
Backstage has iImproper filesystem validation in Bitbucket pull-request scaffolder actions
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @backstage/plugin-scaffolder-backend-module-bitbucket-cloud | < 0.3.10 | 0.3.10 |
| npm | @backstage/plugin-scaffolder-backend-module-bitbucket-server | < 0.2.25 | 0.2.25 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T14:01:26-04:00
MODIFIED 2026-10-07T14:01:29-04:00
INGESTED 2026-10-08T12:30:38-04:00