GHSA-gp6m-x9vw-5c5xMediumCVSS 5.4

Backstage has improper authorization in GitLab organizational user ingestion

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user.

Patches

  • Upgrade @backstage/plugin-catalog-backend-module-gitlab to version 0.8.7.

Workarounds

  • Disable event-driven GitLab organization ingestion and rely on scheduled discovery until upgrading.
  • Enforce organization membership independently at the authenticating proxy or sign-in resolver.

🎯 Affected products1

  • npm/@backstage/plugin-catalog-backend-module-gitlab:< 0.8.7

🔗 References (5)