{"id":"CVE-2026-24046","aliases":["GHSA-rq6q-wr2q-7pgp"],"url":"https://o3.security/vulnerability/CVE-2026-24046","summary":"Backstage has a Possible Symlink Path Traversal in Scaffolder Actions","details":"### Impact\n\nMultiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:\n\n1. **Read arbitrary files** via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets)\n2. **Delete arbitrary files** via the `fs:delete` action by creating symlinks pointing outside the workspace\n3. **Write files outside the workspace** via archive extraction (tar/zip) containing malicious symlinks\n\nThis affects any Backstage deployment where users can create or execute Scaffolder templates.\n\n### Patches\n\nThis vulnerability is fixed in the following package versions:\n\n- `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, 0.15.0\n- `@backstage/plugin-scaffolder-backend` version 2.2.2, 3.0.2, 3.1.1\n- `@backstage/plugin-scaffolder-node` version 0.11.2, 0.12.3\n\nUsers should upgrade to these versions or later.\n\n### Workarounds\n\n- Follow the recommendation in the [Backstage Threat Model](https://backstage.io/docs/overview/threat-model#scaffolder) to limit access to creating and updating templates\n- Restrict who can create and execute Scaffolder templates using the permissions framework\n- Audit existing templates for symlink usage\n- Run Backstage in a containerized environment with limited filesystem access\n\n### References\n\n- [CWE-59: Improper Link Resolution Before File Access](https://cwe.mitre.org/data/definitions/59.html)\n- [OWASP Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal)","published":"2026-01-21T22:36:30.794Z","modified":"2026-08-12T03:51:26.831734153Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@backstage/backend-defaults","fixedVersion":"0.12.2"},{"ecosystem":"npm","name":"@backstage/backend-defaults","fixedVersion":"0.13.2"},{"ecosystem":"npm","name":"@backstage/backend-defaults","fixedVersion":"0.14.1"},{"ecosystem":"npm","name":"@backstage/plugin-scaffolder-backend","fixedVersion":"2.2.2"},{"ecosystem":"npm","name":"@backstage/plugin-scaffolder-backend","fixedVersion":"3.0.2"},{"ecosystem":"npm","name":"@backstage/plugin-scaffolder-backend","fixedVersion":"3.1.1"},{"ecosystem":"npm","name":"@backstage/plugin-scaffolder-node","fixedVersion":"0.11.2"},{"ecosystem":"npm","name":"@backstage/plugin-scaffolder-node","fixedVersion":"0.12.3"}],"fix":{"url":"https://github.com/backstage/backstage/commit/c641c147ab371a9a8a2f5f67fdb7cb9c97ef345d","label":"backstage/backstage@c641c14"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24046.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6174"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6802"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-24046"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24046.json"},{"type":"ADVISORY","url":"https://github.com/backstage/backstage/security/advisories/GHSA-rq6q-wr2q-7pgp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24046"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431878"},{"type":"FIX","url":"https://github.com/backstage/backstage/commit/c641c147ab371a9a8a2f5f67fdb7cb9c97ef345d"},{"type":"PACKAGE","url":"https://github.com/backstage/backstage"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.831734153Z"}}