AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106486.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Impact An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect filesystem paths outside the expected working area. Depending on the backend deployment, this could compromise backend confidentiality, integrity, or availability. ### Patches - `@backstage/plugin-scaffolder-backend-module-bitbucket-cloud` version `0.3.10` - `@backstage/plugin-scaffolder-backend-module-bitbucket-server` version `0.2.25` ### Workarounds - Restrict execution of affected Scaffolder templates to trusted users. - Avoid templates that accept user-controlled target repositories for these actions.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-g8rx-f7m5-7794

Open original source · Updated Oct 07, 2026

Backstage has iImproper filesystem validation in Bitbucket pull-request scaffolder actions

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
npm@backstage/plugin-scaffolder-backend-module-bitbucket-cloud< 0.3.100.3.10
npm@backstage/plugin-scaffolder-backend-module-bitbucket-server< 0.2.250.2.25

Original records & references

PUBLISHED 2026-10-07T14:01:26-04:00
MODIFIED 2026-10-07T14:01:29-04:00
INGESTED 2026-10-08T12:30:38-04:00