GHSA-gp6m-x9vw-5c5x

Suggest an improvement
Source
https://github.com/advisories/GHSA-gp6m-x9vw-5c5x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-gp6m-x9vw-5c5x/GHSA-gp6m-x9vw-5c5x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gp6m-x9vw-5c5x
Aliases
Published
2026-10-07T18:01:39Z
Modified
2026-10-07T18:15:10Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Backstage has improper authorization in GitLab organizational user ingestion
Details

Impact

Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user.

Patches

  • Upgrade @backstage/plugin-catalog-backend-module-gitlab to version 0.8.7.

Workarounds

  • Disable event-driven GitLab organization ingestion and rely on scheduled discovery until upgrading.
  • Enforce organization membership independently at the authenticating proxy or sign-in resolver.
Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T18:01:39Z",
    "nvd_published_at": "2026-10-06T21:17:17Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @backstage/plugin-catalog-backend-module-gitlab

Package

Name
@backstage/plugin-catalog-backend-module-gitlab
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-catalog-backend-module-gitlab

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-gp6m-x9vw-5c5x/GHSA-gp6m-x9vw-5c5x.json"