AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106560.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Impact An authenticated user who can execute an affected template and control its repository file location may cause generated content to be written outside the task workspace, within locations writable by the Backstage backend process. ### Patches Patched in `@backstage/plugin-scaffolder-backend-module-confluence-to-markdown` version `0.3.25` ### Workarounds - Restrict execution of templates using the affected action to trusted users. - Remove or disable the affected action until the patched package is deployed.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-2cmg-v53w-8xfp

Open original source · Updated Oct 07, 2026

Backstage: Improper repository path validation in a Scaffolder backend module

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
npm@backstage/plugin-scaffolder-backend-module-confluence-to-markdown< 0.3.250.3.25

Original records & references

PUBLISHED 2026-10-07T14:02:59-04:00
MODIFIED 2026-10-07T14:03:00-04:00
INGESTED 2026-10-08T12:30:38-04:00