In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-3357
https://about.gitlab.com/releases/categories/releases/
https://about.gitlab.com/releases/2020/03/26/security-release-12-dot-9-dot-1-released/