<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 06:21:01 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275127</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275127</link>
      <description>EUVD-2026-275127</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275127</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30244</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30244</link>
      <description>&lt;p&gt;Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has been patched in version 1.2.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints. This issue has been patched in version 1.2.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30244</guid>
    </item>
    <item>
      <title>GHSA-87x4-j8vh-p5qf — Plane is Vulnerable to Unauthenticated Workspace Member Information Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-87x4-j8vh-p5qf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: plane&lt;/p&gt;
&lt;p&gt;## Executive Summary&lt;/p&gt;
&lt;p&gt;A security vulnerability exists in the Plane project management platform that allows unauthenticated attackers to enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints.&lt;/p&gt;
&lt;p&gt;This vulnerability enables attackers to:&lt;/p&gt;
&lt;p&gt;- Enumerate all members of any workspace without authentication
- Extract user email addresses and personally identifiable information (PII)
- Identify administrative accounts for targeted attacks
- Map organizational structure and user roles
- Conduct reconnaissance for social engineering attacks&lt;/p&gt;
&lt;p&gt;**Affected Endpoints:**&lt;/p&gt;
&lt;p&gt;```
GET /api/public/workspaces/{workspace_slug}/members/
GET /api/public/workspaces/{workspace_slug}/projects/{project_id}/members/
```
A fix is available at https://github.com/makeplane/plane/releases/tag/v1.2.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: plane&lt;/p&gt;
&lt;p&gt;## Executive Summary&lt;/p&gt;
&lt;p&gt;A security vulnerability exists in the Plane project management platform that allows unauthenticated attackers to enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission classes being incorrectly configured to allow anonymous access to protected endpoints.&lt;/p&gt;
&lt;p&gt;This vulnerability enables attackers to:&lt;/p&gt;
&lt;p&gt;- Enumerate all members of any workspace without authentication
- Extract user email addresses and personally identifiable information (PII)
- Identify administrative accounts for targeted attacks
- Map organizational structure and user roles
- Conduct reconnaissance for social engineering attacks&lt;/p&gt;
&lt;p&gt;**Affected Endpoints:**&lt;/p&gt;
&lt;p&gt;```
GET /api/public/workspaces/{workspace_slug}/members/
GET /api/public/workspaces/{workspace_slug}/projects/{project_id}/members/
```
A fix is available at https://github.com/makeplane/plane/releases/tag/v1.2.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-87x4-j8vh-p5qf</guid>
    </item>
  </channel>
</rss>
