A long-lived token embedded in GitLab’s issue-creating email address means anyone with the address, not just the project ...
GitLab’s non-expiring incoming email token can let a holder commit code with a user’s permissions and trigger CI/CD jobs.
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.