Disclosure summary
### Impact Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user. ### Patches - Upgrade `@backstage/plugin-catalog-backend-module-gitlab` to version `0.8.7`. ### Workarounds - Disable event-driven GitLab organization ingestion and rely on scheduled discovery until upgrading. - Enforce organization membership independently at the authenticating proxy or sign-in resolver.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-gp6m-x9vw-5c5x
Open original source · Updated Oct 07, 2026
Backstage has improper authorization in GitLab organizational user ingestion
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @backstage/plugin-catalog-backend-module-gitlab | < 0.8.7 | 0.8.7 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T14:01:39-04:00
MODIFIED 2026-10-07T14:01:39-04:00
INGESTED 2026-10-08T12:30:38-04:00