CVE-2023-35926: high-severity vulnerability in backstage
Insecure sandbox in Backstage Scaffolder plugin
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 1.9%
exploitation probability
1.9%top 21% of all CVEs
observed exploitation
nono source reports it
Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this sandbox so far has been `vm2`, but in light of several past vulnerabilities and existing vulnerabilities that may not have a fix, the plugin has switched to using a different sandbox library. A malicious actor with write access to a registered scaffolder template could manipulate the template in a way that allows for remote code execution on the scaffolder-backend instance. This was only exploitable in the template YAML definition itself and not by user input data. This is vulnerability is fixed in version 1.15.0 of `@backstage/plugin-scaffolder-backend`.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
backstage · backstageRelated CVEs — backstage
In the same product, most dangerous first.
CVE-2021-41151MEDIUMPath Traversal in @backstage/plugin-scaffolder-backendEPSS 1.3%CVE-2021-32662MEDIUMTechDocs mkdocs.yml path traversalEPSS 1.3%CVE-2021-32660MEDIUMTechDocs content sanitization bypassEPSS 1.3%CVE-2021-43783HIGHPath Traversal in @backstage/plugin-scaffolder-backendEPSS 1.2%CVE-2021-32661MEDIUMTechDocs object element script injectionEPSS 1.2%CVE-2026-88064HIGHBackstage: Improper input validation in TechDocs MkDocs configurationEPSS 1.2%