Search

Find a vulnerability

Search criteria

    110 vulnerabilities by makeplane

    CVE-2026-105641 (GCVE-0-2026-105641)

    Vulnerability from nvd – Published: 2026-10-05 18:12 – Updated: 2026-10-05 18:12
    VLAI
    Title
    Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.
    CWE
    • CWE-798 - Use of Hard-coded Credentials
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "CWE-798: Use of Hard-coded Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:12:33.062Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-cmwv-pjmw-8483",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-cmwv-pjmw-8483"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9291",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9291"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/1acc69e816a9a8789032bf711aa9a3c12fcd285c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/1acc69e816a9a8789032bf711aa9a3c12fcd285c"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-cmwv-pjmw-8483",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests \u2014 session forgery and live-server auth bypass"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105641",
        "datePublished": "2026-10-05T18:12:33.062Z",
        "dateReserved": "2026-10-05T16:40:39.612Z",
        "dateUpdated": "2026-10-05T18:12:33.062Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105640 (GCVE-0-2026-105640)

    Vulnerability from nvd – Published: 2026-10-05 18:11 – Updated: 2026-10-05 18:33
    VLAI
    Title
    Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:32 UTC
    CWE
    • CWE-287 - Improper Authentication
    • CWE-290 - Authentication Bypass by Spoofing
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105640",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:32:52.620033Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:33:16.382Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-7j95-vh8g-f365"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity\u0027s unverified provider email to a victim\u0027s address, which Plane matches directly to the victim\u0027s existing local account. The attacker can then log in to the victim\u0027s Plane account without knowing the victim\u0027s password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-290",
                  "description": "CWE-290: Authentication Bypass by Spoofing",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:11:35.680Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-7j95-vh8g-f365",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-7j95-vh8g-f365"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9289",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9289"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/b91b61c379908d9e451613dbca23fc3803e926d2",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/b91b61c379908d9e451613dbca23fc3803e926d2"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-7j95-vh8g-f365",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105640",
        "datePublished": "2026-10-05T18:11:35.680Z",
        "dateReserved": "2026-10-05T16:40:39.612Z",
        "dateUpdated": "2026-10-05T18:33:16.382Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105639 (GCVE-0-2026-105639)

    Vulnerability from nvd – Published: 2026-10-05 18:10 – Updated: 2026-10-05 18:10
    VLAI
    Title
    Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = "all", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target's email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker's initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0.
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    • CWE-287 - Improper Authentication
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane\u0027s signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = \"all\", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target\u0027s email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker\u0027s initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:10:35.787Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-4vj8-p63v-8p24",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-4vj8-p63v-8p24"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9297",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9297"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/6220ba990b2276a1a1979d1d5df68f650b8b47ad",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/6220ba990b2276a1a1979d1d5df68f650b8b47ad"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-4vj8-p63v-8p24",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105639",
        "datePublished": "2026-10-05T18:10:35.787Z",
        "dateReserved": "2026-10-05T16:40:39.612Z",
        "dateUpdated": "2026-10-05T18:10:35.787Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105638 (GCVE-0-2026-105638)

    Vulnerability from nvd – Published: 2026-10-05 18:09 – Updated: 2026-10-05 18:44
    VLAI
    Title
    Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:43 UTC
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105638",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:43:46.990678Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:44:08.562Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-mqjv-rwgv-4gxq"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane\u0027s magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF\u0027s APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:09:35.649Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-mqjv-rwgv-4gxq",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-mqjv-rwgv-4gxq"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9130",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9130"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/b1c78fe4c832e188454840eb38fd20cd05ef8b0a",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/b1c78fe4c832e188454840eb38fd20cd05ef8b0a"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-mqjv-rwgv-4gxq",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105638",
        "datePublished": "2026-10-05T18:09:35.649Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:44:08.562Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105637 (GCVE-0-2026-105637)

    Vulnerability from nvd – Published: 2026-10-05 18:04 – Updated: 2026-10-05 19:09
    VLAI
    Title
    Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, draft_issue_id, or project_id to an entity the attacker controls. Plane then treats the attacker's project as the new owner and provides a presigned download URL for the hijacked file. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 19:09 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105637",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T19:09:42.896444Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T19:09:51.157Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-r2hw-fff3-pjwp"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, draft_issue_id, or project_id to an entity the attacker controls. Plane then treats the attacker\u0027s project as the new owner and provides a presigned download URL for the hijacked file. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 9.6,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:04:02.780Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-r2hw-fff3-pjwp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-r2hw-fff3-pjwp"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9495",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9495"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/15e835710c7f938e0fae9c0ee77bb8162ff436a0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/15e835710c7f938e0fae9c0ee77bb8162ff436a0"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-r2hw-fff3-pjwp",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Cross-Project Asset Hijacking via \u0027ProjectBulkAssetEndpoint\u0027 (sibling of CVE-2026-46558)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105637",
        "datePublished": "2026-10-05T18:04:02.780Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T19:09:51.157Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105636 (GCVE-0-2026-105636)

    Vulnerability from nvd – Published: 2026-10-05 18:02 – Updated: 2026-10-05 18:02
    VLAI
    Title
    Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:02:53.127Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-mq87-52pf-hm3h",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-mq87-52pf-hm3h"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9163",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9163"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-mq87-52pf-hm3h",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105636",
        "datePublished": "2026-10-05T18:02:53.127Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:02:53.127Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105635 (GCVE-0-2026-105635)

    Vulnerability from nvd – Published: 2026-10-05 18:01 – Updated: 2026-10-05 18:41
    VLAI
    Title
    Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:41 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    • CWE-284 - Improper Access Control
    • CWE-862 - Missing Authorization
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105635",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:41:24.401855Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:41:46.850Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-2r58-hgv7-635q"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:01:52.446Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-2r58-hgv7-635q",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-2r58-hgv7-635q"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9305",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9305"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/4b52dce76e8aa97a8d87166fa8f4441c1cf646b1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/4b52dce76e8aa97a8d87166fa8f4441c1cf646b1"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-2r58-hgv7-635q",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105635",
        "datePublished": "2026-10-05T18:01:52.446Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:41:46.850Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105634 (GCVE-0-2026-105634)

    Vulnerability from nvd – Published: 2026-10-05 18:00 – Updated: 2026-10-05 18:00
    VLAI
    Title
    Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles
    Summary
    Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.3.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.3.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member\u0027s role. The authorization check prevents assigning a role higher than the requester\u0027s role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:00:50.831Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-494h-3rcq-5g3c",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-494h-3rcq-5g3c"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/8833",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/8833"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/587fe76032fb69275866fdeb655699a70a83c521",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/587fe76032fb69275866fdeb655699a70a83c521"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.3.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.3.0"
            }
          ],
          "source": {
            "advisory": "GHSA-494h-3rcq-5g3c",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105634",
        "datePublished": "2026-10-05T18:00:50.831Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:00:50.831Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105633 (GCVE-0-2026-105633)

    Vulnerability from nvd – Published: 2026-10-05 17:58 – Updated: 2026-10-05 18:22
    VLAI
    Title
    Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user's attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the issue_id in the URL. When the attachment is pending and has not been confirmed as uploaded, the PATCH handler sets created_by = request.user and transfers attachment ownership to the attacker. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:21 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105633",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:21:45.443968Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:22:11.592Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-5mxw-g5mw-3v3w"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user\u0027s attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the issue_id in the URL. When the attachment is pending and has not been confirmed as uploaded, the PATCH handler sets created_by = request.user and transfers attachment ownership to the attacker. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:58:32.417Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-5mxw-g5mw-3v3w",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-5mxw-g5mw-3v3w"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9315",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9315"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/5829f0febf0739494d576b60d4943d10d236bc96",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/5829f0febf0739494d576b60d4943d10d236bc96"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-5mxw-g5mw-3v3w",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105633",
        "datePublished": "2026-10-05T17:58:32.417Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:22:11.592Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105632 (GCVE-0-2026-105632)

    Vulnerability from nvd – Published: 2026-10-05 17:57 – Updated: 2026-10-05 19:13
    VLAI
    Title
    Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project's visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 19:13 UTC
    CWE
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105632",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T19:13:14.016455Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T19:13:21.788Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-45hc-q4mw-jhxm"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project\u0027s visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:57:22.672Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-45hc-q4mw-jhxm",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-45hc-q4mw-jhxm"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9333",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9333"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/e1ef42023ab66b5e722a8750e1bc5ba0d413a3ee",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/e1ef42023ab66b5e722a8750e1bc5ba0d413a3ee"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-45hc-q4mw-jhxm",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105632",
        "datePublished": "2026-10-05T17:57:22.672Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T19:13:21.788Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105631 (GCVE-0-2026-105631)

    Vulnerability from nvd – Published: 2026-10-05 17:55 – Updated: 2026-10-05 17:55
    VLAI
    Title
    Plane: asset download endpoints scope file lookups to the workspace (not the project / published entity) → cross-project & unauthenticated private-file disclosure
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that grants AllowAny access and scopes the lookup only to the anchor's workspace rather than its published entity or project. An unauthenticated caller who knows a valid anchor and an asset UUID can therefore retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace. This issue is fixed in 1.4.0.
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset\u0027s project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that grants AllowAny access and scopes the lookup only to the anchor\u0027s workspace rather than its published entity or project. An unauthenticated caller who knows a valid anchor and an asset UUID can therefore retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:55:56.166Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-85h2-mhcc-xfmw",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-85h2-mhcc-xfmw"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9288",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9288"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9372",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9372"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/e63f0c3b3404d669ae05dd9050aab72292f87e5c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/e63f0c3b3404d669ae05dd9050aab72292f87e5c"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-85h2-mhcc-xfmw",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: asset download endpoints scope file lookups to the workspace (not the project / published entity) \u2192 cross-project \u0026 unauthenticated private-file disclosure"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105631",
        "datePublished": "2026-10-05T17:55:56.166Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T17:55:56.166Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105630 (GCVE-0-2026-105630)

    Vulnerability from nvd – Published: 2026-10-05 17:54 – Updated: 2026-10-05 18:41
    VLAI
    Title
    Plane: Stored XSS via SVG attachment served inline on the application origin (account takeover)
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Content-Type, and the asset-download endpoint creates a presigned URL with Content-Disposition: inline. In the default self-hosted MinIO deployment, the asset URL is served from the same origin as the Plane application, allowing embedded SVG JavaScript to execute in the application's security context. A victim, including a workspace administrator, who opens the link can have the session compromised through stored XSS, leading to account takeover. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:40 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    • CWE-616 - Incomplete Identification of Uploaded File Variables (PHP)
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105630",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:40:36.143539Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:41:01.196Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-ch8j-vr4r-qf6h"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Content-Type, and the asset-download endpoint creates a presigned URL with Content-Disposition: inline. In the default self-hosted MinIO deployment, the asset URL is served from the same origin as the Plane application, allowing embedded SVG JavaScript to execute in the application\u0027s security context. A victim, including a workspace administrator, who opens the link can have the session compromised through stored XSS, leading to account takeover. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434: Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-616",
                  "description": "CWE-616: Incomplete Identification of Uploaded File Variables (PHP)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:54:01.999Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-ch8j-vr4r-qf6h",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-ch8j-vr4r-qf6h"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9312",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9312"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/9dff20e04808286acb372119d88c666b802b1d50",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/9dff20e04808286acb372119d88c666b802b1d50"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-ch8j-vr4r-qf6h",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Stored XSS via SVG attachment served inline on the application origin (account takeover)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105630",
        "datePublished": "2026-10-05T17:54:01.999Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:41:01.196Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105629 (GCVE-0-2026-105629)

    Vulnerability from nvd – Published: 2026-10-05 17:53 – Updated: 2026-10-05 17:53
    VLAI
    Title
    Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped Primary Key Lookup
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0.
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker\u0027s own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:53:01.671Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-7mr3-6cgx-3j95",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-7mr3-6cgx-3j95"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9286",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9286"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/971c2aadb4e848d70676b4f58b94bc7992dfe5fc",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/971c2aadb4e848d70676b4f58b94bc7992dfe5fc"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-7mr3-6cgx-3j95",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped Primary Key Lookup"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105629",
        "datePublished": "2026-10-05T17:53:01.671Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T17:53:01.671Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105628 (GCVE-0-2026-105628)

    Vulnerability from nvd – Published: 2026-10-05 17:51 – Updated: 2026-10-05 17:57
    VLAI
    Title
    Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Static Asset Endpoint
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response as a user avatar file. The object is then exposed through /api/assets/v2/static/{asset_id}/, allowing exfiltration of internally fetched content. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 17:56 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105628",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T17:56:44.537944Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T17:57:41.515Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-cv9p-325g-wmv5"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane\u0027s OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response as a user avatar file. The object is then exposed through /api/assets/v2/static/{asset_id}/, allowing exfiltration of internally fetched content. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:51:01.044Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-cv9p-325g-wmv5",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-cv9p-325g-wmv5"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9163",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9163"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-cv9p-325g-wmv5",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Static Asset Endpoint"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105628",
        "datePublished": "2026-10-05T17:51:01.044Z",
        "dateReserved": "2026-10-05T16:40:39.610Z",
        "dateUpdated": "2026-10-05T17:57:41.515Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104979 (GCVE-0-2026-104979)

    Vulnerability from nvd – Published: 2026-10-05 17:49 – Updated: 2026-10-05 19:12
    VLAI
    Title
    Plane: Cross-tenant stored XSS in intake enables account takeover
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="_self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 19:11 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    • CWE-862 - Missing Authorization
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104979",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T19:11:49.930509Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T19:12:00.312Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-hh2r-3hwp-mvq3"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \\tjavascript: parser bypass and the target=\"_self\" click handler execute JavaScript in the viewer\u0027s session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:49:53.030Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-hh2r-3hwp-mvq3",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-hh2r-3hwp-mvq3"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9287",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9287"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/0d58adb69d859fc94c43b9d68fadd77e810d5ed1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/0d58adb69d859fc94c43b9d68fadd77e810d5ed1"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-hh2r-3hwp-mvq3",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Cross-tenant stored XSS in intake enables account takeover"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104979",
        "datePublished": "2026-10-05T17:49:53.030Z",
        "dateReserved": "2026-10-02T18:16:13.629Z",
        "dateUpdated": "2026-10-05T19:12:00.312Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104978 (GCVE-0-2026-104978)

    Vulnerability from nvd – Published: 2026-10-05 17:48 – Updated: 2026-10-05 17:48
    VLAI
    Title
    Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acceptance
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attacker can enumerate the invitation, register an account using the invited email without mailbox verification, and accept the invitation. The attacker-controlled account is then added to the target workspace and project. This issue is fixed in 1.4.0.
    CWE
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane\u0027s project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attacker can enumerate the invitation, register an account using the invited email without mailbox verification, and accept the invitation. The attacker-controlled account is then added to the target workspace and project. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:48:34.948Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-g36h-p63v-g9c7",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-g36h-p63v-g9c7"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9308",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9308"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/14a4c22f94eac1582439e41112213f976c6a6cf7",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/14a4c22f94eac1582439e41112213f976c6a6cf7"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-g36h-p63v-g9c7",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acceptance"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104978",
        "datePublished": "2026-10-05T17:48:34.948Z",
        "dateReserved": "2026-10-02T18:16:13.629Z",
        "dateUpdated": "2026-10-05T17:48:34.948Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104977 (GCVE-0-2026-104977)

    Vulnerability from nvd – Published: 2026-10-05 17:47 – Updated: 2026-10-05 18:40
    VLAI
    Title
    Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is_blocked_ip (CGNAT/multicast) + DNS-rebinding TOCTOU
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the link title or favicon. Complete hardening exists on main in PR 9163 but was not included in an earlier released tag. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:39 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104977",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:39:50.576750Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:40:11.398Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-hhj8-7hv6-m74r"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the link title or favicon. Complete hardening exists on main in PR 9163 but was not included in an earlier released tag. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:47:29.989Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-hhj8-7hv6-m74r",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-hhj8-7hv6-m74r"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9163",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9163"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-hhj8-7hv6-m74r",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Incomplete fix of CVE-2026-27706 \u2014 SSRF still reachable on: missing is_blocked_ip (CGNAT/multicast) + DNS-rebinding TOCTOU"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104977",
        "datePublished": "2026-10-05T17:47:29.989Z",
        "dateReserved": "2026-10-02T18:16:13.629Z",
        "dateUpdated": "2026-10-05T18:40:11.398Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104976 (GCVE-0-2026-104976)

    Vulnerability from nvd – Published: 2026-10-05 17:45 – Updated: 2026-10-05 17:45
    VLAI
    Title
    Plane: SSRF in Gitea OAuth
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane validates GITEA_HOST only for its URL scheme and does not reject hosts that resolve to private or internal IP addresses. The four outbound requests in the Gitea OAuth flow are derived from this unvalidated host and do not call validate_url(). In addition, avatar_url is taken from the Gitea user's profile, where users can configure external avatar URLs. After an administrator enables Gitea OAuth for a legitimate instance, a Gitea user can set an internal URL as the profile avatar and log in through Gitea, causing Plane to fetch the internal target without validation. This issue is fixed in 1.4.0.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane validates GITEA_HOST only for its URL scheme and does not reject hosts that resolve to private or internal IP addresses. The four outbound requests in the Gitea OAuth flow are derived from this unvalidated host and do not call validate_url(). In addition, avatar_url is taken from the Gitea user\u0027s profile, where users can configure external avatar URLs. After an administrator enables Gitea OAuth for a legitimate instance, a Gitea user can set an internal URL as the profile avatar and log in through Gitea, causing Plane to fetch the internal target without validation. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:45:43.115Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-hx79-5pj5-qh42",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-hx79-5pj5-qh42"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9163",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9163"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-hx79-5pj5-qh42",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: SSRF in Gitea OAuth"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104976",
        "datePublished": "2026-10-05T17:45:43.115Z",
        "dateReserved": "2026-10-02T18:16:13.629Z",
        "dateUpdated": "2026-10-05T17:45:43.115Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104975 (GCVE-0-2026-104975)

    Vulnerability from nvd – Published: 2026-10-05 17:44 – Updated: 2026-10-05 18:00
    VLAI
    Title
    Plane: Cross-tenant asset authorization bypass in Plane Spaces public-board endpoints
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints in that file. The Spaces app in plane/space/views/asset.py serves related public-board operations under /api/public/ but was not remediated. Its EntityAssetEndpoint and AssetRestoreEndpoint resolve a DeployBoard from a public anchor and then read or modify FileAsset rows scoped only to the board's workspace, without a membership check or project_id constraint. An attacker can therefore read, overwrite, or restore assets across projects and workspaces. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 17:59 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104975",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T17:59:48.150470Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:00:17.007Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-jh4v-88j2-g65v"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane\u0027s dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints in that file. The Spaces app in plane/space/views/asset.py serves related public-board operations under /api/public/ but was not remediated. Its EntityAssetEndpoint and AssetRestoreEndpoint resolve a DeployBoard from a public anchor and then read or modify FileAsset rows scoped only to the board\u0027s workspace, without a membership check or project_id constraint. An attacker can therefore read, overwrite, or restore assets across projects and workspaces. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:44:24.414Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-jh4v-88j2-g65v",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-jh4v-88j2-g65v"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9288",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9288"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-jh4v-88j2-g65v",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Cross-tenant asset authorization bypass in Plane Spaces public-board endpoints"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104975",
        "datePublished": "2026-10-05T17:44:24.414Z",
        "dateReserved": "2026-10-02T18:16:13.629Z",
        "dateUpdated": "2026-10-05T18:00:17.007Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104974 (GCVE-0-2026-104974)

    Vulnerability from nvd – Published: 2026-10-05 17:42 – Updated: 2026-10-05 19:07
    VLAI
    Title
    Plane: Disabled User Auto-Reactivation on Login
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 19:07 UTC
    CWE
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104974",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T19:07:46.716051Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T19:07:53.615Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-rmmf-rj2q-3rrg"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:42:45.210Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-rmmf-rj2q-3rrg",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-rmmf-rj2q-3rrg"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9290",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9290"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9304",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9304"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/1e8f3630c7697129b61eb57f2453f0bf09224920",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/1e8f3630c7697129b61eb57f2453f0bf09224920"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/6c9dbb50434d16ea00a00d1574723dfd0c3d2446",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/6c9dbb50434d16ea00a00d1574723dfd0c3d2446"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-rmmf-rj2q-3rrg",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Disabled User Auto-Reactivation on Login"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104974",
        "datePublished": "2026-10-05T17:42:45.210Z",
        "dateReserved": "2026-10-02T18:16:13.629Z",
        "dateUpdated": "2026-10-05T19:07:53.615Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104973 (GCVE-0-2026-104973)

    Vulnerability from nvd – Published: 2026-10-05 17:41 – Updated: 2026-10-05 17:41
    VLAI
    Title
    Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypass the SSRF protection. This issue is fixed in 1.4.0.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypass the SSRF protection. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.6,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:41:33.110Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-whh3-5g95-4qhc",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-whh3-5g95-4qhc"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9163",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9163"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-whh3-5g95-4qhc",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104973",
        "datePublished": "2026-10-05T17:41:33.110Z",
        "dateReserved": "2026-10-02T18:16:13.629Z",
        "dateUpdated": "2026-10-05T17:41:33.110Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104971 (GCVE-0-2026-104971)

    Vulnerability from nvd – Published: 2026-10-05 17:04 – Updated: 2026-10-05 18:38
    VLAI
    Title
    Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEndpoint Missing Authorization
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:38 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    • CWE-862 - Missing Authorization
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104971",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:38:20.168300Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:38:43.742Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-p57q-8hh8-7fc7"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller\u0027s workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T17:04:27.821Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-p57q-8hh8-7fc7",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-p57q-8hh8-7fc7"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/8885",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/8885"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9288",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9288"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/ac11c3ef7939e31201fa92a17de106906025590f",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/ac11c3ef7939e31201fa92a17de106906025590f"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-p57q-8hh8-7fc7",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEndpoint Missing Authorization"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104971",
        "datePublished": "2026-10-05T17:04:27.821Z",
        "dateReserved": "2026-10-02T18:16:13.629Z",
        "dateUpdated": "2026-10-05T18:38:43.742Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105641 (GCVE-0-2026-105641)

    Vulnerability from cvelistv5 – Published: 2026-10-05 18:12 – Updated: 2026-10-05 18:12
    VLAI
    Title
    Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.
    CWE
    • CWE-798 - Use of Hard-coded Credentials
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "CWE-798: Use of Hard-coded Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:12:33.062Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-cmwv-pjmw-8483",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-cmwv-pjmw-8483"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9291",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9291"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/1acc69e816a9a8789032bf711aa9a3c12fcd285c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/1acc69e816a9a8789032bf711aa9a3c12fcd285c"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-cmwv-pjmw-8483",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests \u2014 session forgery and live-server auth bypass"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105641",
        "datePublished": "2026-10-05T18:12:33.062Z",
        "dateReserved": "2026-10-05T16:40:39.612Z",
        "dateUpdated": "2026-10-05T18:12:33.062Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105640 (GCVE-0-2026-105640)

    Vulnerability from cvelistv5 – Published: 2026-10-05 18:11 – Updated: 2026-10-05 18:33
    VLAI
    Title
    Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to the victim's existing local account. The attacker can then log in to the victim's Plane account without knowing the victim's password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:32 UTC
    CWE
    • CWE-287 - Improper Authentication
    • CWE-290 - Authentication Bypass by Spoofing
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105640",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:32:52.620033Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:33:16.382Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-7j95-vh8g-f365"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity\u0027s unverified provider email to a victim\u0027s address, which Plane matches directly to the victim\u0027s existing local account. The attacker can then log in to the victim\u0027s Plane account without knowing the victim\u0027s password. GitHub, GitLab.com, and Google are not affected because those providers return verified email addresses. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-290",
                  "description": "CWE-290: Authentication Bypass by Spoofing",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:11:35.680Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-7j95-vh8g-f365",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-7j95-vh8g-f365"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9289",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9289"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/b91b61c379908d9e451613dbca23fc3803e926d2",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/b91b61c379908d9e451613dbca23fc3803e926d2"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-7j95-vh8g-f365",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105640",
        "datePublished": "2026-10-05T18:11:35.680Z",
        "dateReserved": "2026-10-05T16:40:39.612Z",
        "dateUpdated": "2026-10-05T18:33:16.382Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105639 (GCVE-0-2026-105639)

    Vulnerability from cvelistv5 – Published: 2026-10-05 18:10 – Updated: 2026-10-05 18:10
    VLAI
    Title
    Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = "all", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target's email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker's initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0.
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    • CWE-287 - Improper Authentication
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane\u0027s signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = \"all\", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target\u0027s email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker\u0027s initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:10:35.787Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-4vj8-p63v-8p24",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-4vj8-p63v-8p24"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9297",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9297"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/6220ba990b2276a1a1979d1d5df68f650b8b47ad",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/6220ba990b2276a1a1979d1d5df68f650b8b47ad"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-4vj8-p63v-8p24",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105639",
        "datePublished": "2026-10-05T18:10:35.787Z",
        "dateReserved": "2026-10-05T16:40:39.612Z",
        "dateUpdated": "2026-10-05T18:10:35.787Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105638 (GCVE-0-2026-105638)

    Vulnerability from cvelistv5 – Published: 2026-10-05 18:09 – Updated: 2026-10-05 18:44
    VLAI
    Title
    Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:43 UTC
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105638",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:43:46.990678Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:44:08.562Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-mqjv-rwgv-4gxq"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, Plane\u0027s magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF\u0027s APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "CWE-307: Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:09:35.649Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-mqjv-rwgv-4gxq",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-mqjv-rwgv-4gxq"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9130",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9130"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/b1c78fe4c832e188454840eb38fd20cd05ef8b0a",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/b1c78fe4c832e188454840eb38fd20cd05ef8b0a"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-mqjv-rwgv-4gxq",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105638",
        "datePublished": "2026-10-05T18:09:35.649Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:44:08.562Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105637 (GCVE-0-2026-105637)

    Vulnerability from cvelistv5 – Published: 2026-10-05 18:04 – Updated: 2026-10-05 19:09
    VLAI
    Title
    Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, draft_issue_id, or project_id to an entity the attacker controls. Plane then treats the attacker's project as the new owner and provides a presigned download URL for the hijacked file. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 19:09 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105637",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T19:09:42.896444Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T19:09:51.157Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-r2hw-fff3-pjwp"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, draft_issue_id, or project_id to an entity the attacker controls. Plane then treats the attacker\u0027s project as the new owner and provides a presigned download URL for the hijacked file. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 9.6,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:04:02.780Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-r2hw-fff3-pjwp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-r2hw-fff3-pjwp"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9495",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9495"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/15e835710c7f938e0fae9c0ee77bb8162ff436a0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/15e835710c7f938e0fae9c0ee77bb8162ff436a0"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-r2hw-fff3-pjwp",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Cross-Project Asset Hijacking via \u0027ProjectBulkAssetEndpoint\u0027 (sibling of CVE-2026-46558)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105637",
        "datePublished": "2026-10-05T18:04:02.780Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T19:09:51.157Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105636 (GCVE-0-2026-105636)

    Vulnerability from cvelistv5 – Published: 2026-10-05 18:02 – Updated: 2026-10-05 18:02
    VLAI
    Title
    Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0.
    CWE
    • CWE-918 - Server-Side Request Forgery (SSRF)
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918: Server-Side Request Forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:02:53.127Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-mq87-52pf-hm3h",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-mq87-52pf-hm3h"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9163",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9163"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-mq87-52pf-hm3h",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105636",
        "datePublished": "2026-10-05T18:02:53.127Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:02:53.127Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105635 (GCVE-0-2026-105635)

    Vulnerability from cvelistv5 – Published: 2026-10-05 18:01 – Updated: 2026-10-05 18:41
    VLAI
    Title
    Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token
    Summary
    Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 18:41 UTC
    CWE
    • CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor
    • CWE-284 - Improper Access Control
    • CWE-862 - Missing Authorization
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-105635",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T18:41:24.401855Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T18:41:46.850Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/makeplane/plane/security/advisories/GHSA-2r58-hgv7-635q"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-200",
                  "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862: Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:01:52.446Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-2r58-hgv7-635q",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-2r58-hgv7-635q"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/9305",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/9305"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/4b52dce76e8aa97a8d87166fa8f4441c1cf646b1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/4b52dce76e8aa97a8d87166fa8f4441c1cf646b1"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.4.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.4.0"
            }
          ],
          "source": {
            "advisory": "GHSA-2r58-hgv7-635q",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105635",
        "datePublished": "2026-10-05T18:01:52.446Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:41:46.850Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-105634 (GCVE-0-2026-105634)

    Vulnerability from cvelistv5 – Published: 2026-10-05 18:00 – Updated: 2026-10-05 18:00
    VLAI
    Title
    Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles
    Summary
    Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    makeplane plane Affected: < 1.3.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "plane",
              "vendor": "makeplane",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 1.3.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member\u0027s role. The authorization check prevents assigning a role higher than the requester\u0027s role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T18:00:50.831Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/makeplane/plane/security/advisories/GHSA-494h-3rcq-5g3c",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/makeplane/plane/security/advisories/GHSA-494h-3rcq-5g3c"
            },
            {
              "name": "https://github.com/makeplane/plane/pull/8833",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/pull/8833"
            },
            {
              "name": "https://github.com/makeplane/plane/commit/587fe76032fb69275866fdeb655699a70a83c521",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/commit/587fe76032fb69275866fdeb655699a70a83c521"
            },
            {
              "name": "https://github.com/makeplane/plane/releases/tag/v1.3.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/makeplane/plane/releases/tag/v1.3.0"
            }
          ],
          "source": {
            "advisory": "GHSA-494h-3rcq-5g3c",
            "discovery": "UNKNOWN"
          },
          "title": "Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-105634",
        "datePublished": "2026-10-05T18:00:50.831Z",
        "dateReserved": "2026-10-05T16:40:39.611Z",
        "dateUpdated": "2026-10-05T18:00:50.831Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }