CVE-2023-35926
CVE-2023-35926 is a high-severity vulnerability in Linuxfoundation Backstage with a CVSS 3.x base score of 8.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: High (CVSS 3.x base score 8.0)
- EPSS exploit prediction: 2% (78th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Linuxfoundation Backstage
- Published:
- Last modified:
Description
Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this sandbox so far has been `vm2`, but in light of several past vulnerabilities and existing vulnerabilities that may not have a fix, the plugin has switched to using a different sandbox library. A malicious actor with write access to a registered scaffolder template could manipulate the template in a way that allows for remote code execution on the scaffolder-backend instance. This was only exploitable in the template YAML definition itself and not by user input data. This is vulnerability is fixed in version 1.15.0 of `@backstage/plugin-scaffolder-backend`.
Frequently asked questions
- What is CVE-2023-35926?
- Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this sandbox so far has been `vm2`, but in light of several past vulnerabilities and existing vulnerabilities that may not have a fix, the plugin has switched to using a different sandbox library. A malicious actor with write access to a registered scaffolder template could manipulate the template in a way that allows for remote code execution on the scaffolder-backend instance. This was only exploitable in the template YAML definition itself and not by user input data. This is vulnerability is fixed in version 1.15.0 of `@backstage/plugin-scaffolder-backend`.
- How severe is CVE-2023-35926?
- CVE-2023-35926 has a CVSS 3.x base score of 8.0, rated high severity. It is exploitable over network with high attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-35926 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (78th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-35926?
- CVE-2023-35926 affects Linuxfoundation Backstage. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-35926?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2023-35926 published?
- CVE-2023-35926 was published on 2023-06-22 and last updated on 2026-06-17.
References
- https://github.com/backstage/backstage/commit/fb7375507d56faedcb7bb3665480070593c8949a
- https://github.com/backstage/backstage/releases/tag/v1.15.0
- https://github.com/backstage/backstage/security/advisories/GHSA-wg6p-jmpc-xjmr
Affected products (1)
- cpe:2.3:a:linuxfoundation:backstage:*:*:*:*:*:*:*:*
More vulnerabilities in Linuxfoundation Backstage
- CVE-2021-43783 — High (CVSS 8.5): @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions…
- CVE-2026-25153 — High (CVSS 7.7): Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common…
- CVE-2026-32236 — High (CVSS 7.5): Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF)…
- CVE-2021-41151 — Medium (CVSS 6.8): Backstage is an open platform for building developer portals. In affected versions A malicious actor could read…
- CVE-2024-46976 — Medium (CVSS 6.5): Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs…
- CVE-2024-45816 — Medium (CVSS 6.5): Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for…
All CVEs affecting Linuxfoundation Backstage →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-76605 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-76604 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The…
- CVE-2026-67364 — Critical (CVSS 10.0): Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1:…
- CVE-2026-73343 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- CVE-2026-74253 — Critical (CVSS 10.0): Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0…
- CVE-2026-73678 — Critical (CVSS 10.0): MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that…