{"id":"CVE-2026-32237","aliases":["GHSA-8wq8-6859-qx77"],"url":"https://o3.security/vulnerability/CVE-2026-32237","summary":"@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint","details":"### Impact                                                                                                                                                                         \n                                         \n  Authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly \n  redacted in log output but not in all parts of the response payload.\n                                                                                                                                                                                     \n  Deployments that have configured `scaffolder.defaultEnvironment.secrets` are affected.\n                          \n  ### Patches                            \n\n  This is patched in `@backstage/plugin-scaffolder-backend` version 3.1.5\n  ### Workarounds\n\n  Remove or empty the `scaffolder.defaultEnvironment.secrets` configuration from `app-config.yaml`. Alternatively, restrict access to the scaffolder dry-run functionality via the\n  permissions framework.\n\n  ### References\n\n  - [Backstage Scaffolder Backend documentation](https://backstage.io/docs/features/software-templates/)","published":"2026-03-12T18:38:57.156Z","modified":"2026-08-12T03:51:32.152599223Z","cvss":{"score":4.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@backstage/plugin-scaffolder-backend","fixedVersion":"3.1.5"}],"fix":{"url":"https://github.com/backstage/backstage/commit/3b62dd2d6bf7623ebd23e4b5a6dceb209f98dfce","label":"backstage/backstage@3b62dd2"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32237.json"},{"type":"ADVISORY","url":"https://github.com/backstage/backstage/security/advisories/GHSA-8wq8-6859-qx77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32237"},{"type":"FIX","url":"https://github.com/backstage/backstage/commit/3b62dd2d6bf7623ebd23e4b5a6dceb209f98dfce"},{"type":"PACKAGE","url":"https://github.com/backstage/backstage"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.152599223Z"}}