Plane 是一款开源的项目管理工具。在 1.4.0 版本之前,拥有角色 15 的项目成员可以通过向项目成员更新端点 发送 PATCH 请求,更改其他用户的项目角色。角色更新逻辑仅阻止将角色设置为高于请求者当前角色的级别,因此,通过将角色设置为与请求者相同的“成员(Member)”角色,可以绕过验证不足的问题,将原本为“访客(Guest)”(角色 5)的用户提升为“成员”,而无需项目经理的批准。这种未经授权的权限提升使得访客获得了与“成员”角色相关联的项目权限,并允许普通成员绕过项目治理控制。该问题已在 1.4.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105636 | 9.9 CRITICAL | Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) |
| CVE-2026-105639 | 9.8 CRITICAL | Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation tok |
| CVE-2026-105641 | 9.8 CRITICAL | Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deploy |
| CVE-2026-105637 | 9.6 CRITICAL | Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-4 |
| CVE-2026-105638 | 9.1 CRITICAL | Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force |
| CVE-2026-105640 | 9.1 CRITICAL | Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) |
| CVE-2026-104968 | 8.7 HIGH | Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/ |
| CVE-2026-105630 | 8.7 HIGH | Plane: Stored XSS via SVG attachment served inline on the application origin (account take |
| CVE-2026-105632 | 8.7 HIGH | Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private |
| CVE-2026-104979 | 8.7 HIGH | Plane: Cross-tenant stored XSS in intake enables account takeover |
| CVE-2026-104976 | 8.7 HIGH | Plane: SSRF in Gitea OAuth |
| CVE-2026-104966 | 8.7 HIGH | Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Modify, and Inj |
| CVE-2026-104892 | 8.7 HIGH | Plane: Plaintext logging of API token |
| CVE-2026-104971 | 8.5 HIGH | Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEn |
| CVE-2026-104978 | 8.2 HIGH | Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acc |
| CVE-2026-105634 | 8.1 HIGH | Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles |
| CVE-2026-104974 | 8.1 HIGH | Plane: Disabled User Auto-Reactivation on Login |
| CVE-2026-104970 | 8.1 HIGH | Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthenticated calle |
| CVE-2026-104977 | 7.7 HIGH | Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is_blocked_ip ( |
| CVE-2026-105628 | 7.6 HIGH | Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Static Asset End |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet