BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-33395
https://blog.blacklanternsecurity.com/p/bbot-security-advisory-gitdumper