Aikido Security found GitLab's per-user issue email doubles as a non-expiring token that can commit code as the account owner.