Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/@backstage/plugin-scaffolder-backend — 7 CVEs · VulnScope
pkg:npm/
@backstage/plugin-scaffolder-backend
7 total CVEs
HIGH
3
MEDIUM
2
LOW
2
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.5
CVE-2021-43783
Path Traversal in @backstage/plugin-scaffolder-backend
from 0, < 0.15.14
HIGH
8.0
CVE-2023-35926
Backstage Scaffolder plugin has insecure sandbox
from 0, < 1.15.0
HIGH
7.1
CVE-2026-24046
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
from 0, < 2.2.2
MEDIUM
6.8
Path Traversal in @backstage/plugin-scaffolder-backend
>= 0.9.4, < 0.15.9
MEDIUM
4.4
@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint
>= 3.1.0, < 3.1.5
LOW
2.6
Template Secret leakage in logs in Scaffolder when using `fetch:template`
from 0, < 2.1.1
LOW
2.0
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
from 0, < 3.1.4
CVE-2021-41151
CVE-2026-32237
CVE-2025-55285
CVE-2026-29184