Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.41% | — | Linuxfoundation Backstage/plugin-scaffolder-backend | 12/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly redacted in log output but not in all parts of the response… | |
| Analizada | Media (6.5) | 0.30% | — | Linuxfoundation Backstage/plugin-scaffolder-backend | 7/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4. | |
| Aplazada | Alta (7.1) | 0.53% | — | Backstage Backend-defaultsAIBackstage Plugin-scaffolder-backendAIBackstage Plugin-scaffolder-nodeAI | 21/1/2026 | 15/7/2026 | Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log`… | |
| Aplazada | Baja (2.6) | 0.24% | — | Backstage Plugin-scaffolder-backendAI | 15/8/2025 | 17/6/2026 | @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly redacted. If ${{ secrets.x }} is not passed through to… | |
| Aplazada | Media (4.3) | 0.29% | — | Backstage PermissionsAIBackstage ScaffolderAI | 16/4/2025 | 17/6/2026 | The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in the Backstage permission plugin backend allows callers to extract some information about the conditional decisions returned by the permission policy installed in the permission backend. If the… | |
| Aplazada | Media (5.4) | 0.37% | — | Backstage Plugin-scaffolder-nodeAI | 29/11/2024 | 17/6/2026 | The Backstage Scaffolder plugin Houses types and utilities for building scaffolder-related modules. A vulnerability is identified in Backstage Scaffolder template functionality where Server-Side Template Injection (SSTI) can be exploited to perform Git config injection. The vulnerability allows an attacker to capture… |