GHSA-gp6m-x9vw-5c5xMediumCVSS 5.4
Backstage has improper authorization in GitLab organizational user ingestion
🔗 CVE IDs covered (1)
📋 Description
Impact
Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user.
Patches
- Upgrade
@backstage/plugin-catalog-backend-module-gitlabto version0.8.7.
Workarounds
- Disable event-driven GitLab organization ingestion and rely on scheduled discovery until upgrading.
- Enforce organization membership independently at the authenticating proxy or sign-in resolver.
🎯 Affected products1
- npm/@backstage/plugin-catalog-backend-module-gitlab:< 0.8.7
🔗 References (5)
- https://github.com/backstage/backstage/security/advisories/GHSA-gp6m-x9vw-5c5x
- https://nvd.nist.gov/vuln/detail/CVE-2026-106463
- https://github.com/backstage/backstage/commit/c211b4b67d28efd2f4fac63e35e2ac515e305cb3
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-gp6m-x9vw-5c5x