Detects GitLab EE instances where the aiSelfHostedModels GraphQL query is accessible without authentication, exposing self-hosted AI model configurations including plaintext API tokens for LLM providers. Affects GitLab EE 18.5.0–18.8.6, 18.9.0–18.9.2, and 18.10.0.
Is your app exploitable through CVE-2026-1724?
Scan your domain free