Vulnerability Description
Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly redacted in log output but not in all parts of the response payload. Deployments that have configured scaffolder.defaultEnvironment.secrets are affected. This is patched in @backstage/plugin-scaffolder-backend version 3.1.5.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Backstage\/Plugin-Scaffolder-Backend | >= 3.1.0, < 3.1.5 |
Related Weaknesses (CWE)
References
- https://github.com/backstage/backstage/commit/3b62dd2d6bf7623ebd23e4b5a6dceb209fPatch
- https://github.com/backstage/backstage/security/advisories/GHSA-8wq8-6859-qx77Vendor Advisory
FAQ
What is CVE-2026-32237?
CVE-2026-32237 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secre...
How severe is CVE-2026-32237?
CVE-2026-32237 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-32237?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Backstage\/Plugin-Scaffolder-Backend.