Executive brief
Backstage, a platform used to build internal developer portals, contains a vulnerability in its Scaffolder component which automates software creation. An attacker with the ability to create or run templates could use specially crafted links (symlinks) to bypass security boundaries. This could allow them to read sensitive system files like passwords and secrets, delete important data, or write unauthorized files to the server, potentially leading to a full system compromise or data breach.
Technical details
A path traversal vulnerability exists in Backstage due to improper link resolution (CWE-59) and insufficient path neutralization (CWE-22) within Scaffolder actions and archive extraction utilities. An attacker with low-privileged network access to create or execute Scaffolder templates can use malicious symlinks to escape the workspace directory. Specifically, the 'debug:log' action can be abused to read arbitrary files (e.g., /etc/passwd), 'fs:delete' can be used to delete files outside the workspace, and tar/zip extraction can be used to write files to unauthorized locations. The fix involves implementing 'resolveSafeChildPath' to ensure all file operations remain within the designated sandbox.
Affected products
- Backstage Backstage backend-defaults < 0.12.2, 0.13.0 - 0.13.2, 0.14.0 - 0.14.1
- Backstage Backstage plugin-scaffolder-backend < 2.2.2, 3.0.0 - 3.0.2, 3.1.0 - 3.1.1
- Backstage Backstage plugin-scaffolder-node < 0.11.2, 0.12.0 - 0.12.3
- Red Hat Red Hat Developer Hub 1.8, 1.9
Timeline
- 2026-01-20: patched: Fix committed to Backstage repository.
- 2026-01-21: advisory: GitHub Security Advisory GHSA-rq6q-wr2q-7pgp published.
- 2026-01-21: disclosed: CVE-2026-24046 published.
- 2026-03-30: advisory: Red Hat issued security advisory RHSA-2026:6174 for Developer Hub.
References
- https://github.com/backstage/backstage/commit/c641c147ab371a9a8a2f5f67fdb7cb9c97ef345d
- https://github.com/backstage/backstage/security/advisories/GHSA-rq6q-wr2q-7pgp
- https://access.redhat.com/errata/RHSA-2026:6174
- https://access.redhat.com/errata/RHSA-2026:6802
- https://access.redhat.com/security/cve/CVE-2026-24046
- https://bugzilla.redhat.com/show_bug.cgi?id=2431878
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24046.json