CVE-2026-32237Disclosure(linuxfoundation / backstage\/plugin-scaffolder-backend)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation backstage\/plugin-scaffolder-backend systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly redacted in log output but not in all parts of the response payload. Deployments that have configured scaffolder.defaultEnvironment.secrets are affected. This is patched in @backstage/plugin-scaffolder-backend version 3.1.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • backstage\/plugin-scaffolder-backend

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
backstage\/plugin-scaffolder-backend

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-12: 3Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 303-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32237 Authenticated Secret Exposure in Backstage Scaffolder Dry-Run API Before 3.1.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32237

    Post summary

    A security vulnerability (CVE-2026-32237) involving authenticated secret exposure in Backstage Scaffolder's dry‑run API before version 3.1.5 has been identified, but no proof of concept, exploit, active exploitation, or patch details are provided.

    0000025
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 @backstage/plugin-scaffolder-backend: Information Exposure, #CVE-2026-32237 (Moderate) https://dailycve.com/backstage-plugin-scaffolder-backend-information-exposure-cve-2026-32237-moderate/

    Post summary

    The tweet announces the disclosure of CVE‑2026‑32237, an information‑exposure vulnerability of moderate severity, without any mention of PoC, exploits, or patches.

    0000026
    168 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32237 Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to s… https://www.cve.org/CVERecord?id=CVE-2026-32237

    Post summary

    CVE-2026-32237 describes an access control flaw in Backstage for users with scaffolder dry‑run permissions before version 3.1.5; no PoC, exploit, or active exploitation is reported, but the fix is implied by the version number.

    00000132
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationbackstage\/plugin-scaffolder-backend-node.js-

Explore more