Plane 是一个开源的项目管理工具。在 1.4.0 版本之前,有两类 API 端点未验证嵌套资源标识符是否属于 URL 中指定的工作区(workspace)和项目(project)。已认证用户可以通过以下两个接口读取或修改其他工作区中的估算数据,并向其他工作区中的问题注入评论: 通过 接口读取或修改估算; 通过 接口向其他工作区中的问题添加评论。 尽管 会验证 URL 中指定的工作区和项目中的成员资格,但 和 是通过主键直接获取的,并未确认其是否与当前作用域一致。列表(list)、详情(retrieve)和删除(
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105636 | 9.9 CRITICAL | Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) |
| CVE-2026-105639 | 9.8 CRITICAL | Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation tok |
| CVE-2026-105641 | 9.8 CRITICAL | Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deploy |
| CVE-2026-105637 | 9.6 CRITICAL | Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-4 |
| CVE-2026-105638 | 9.1 CRITICAL | Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force |
| CVE-2026-105640 | 9.1 CRITICAL | Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) |
| CVE-2026-104968 | 8.7 HIGH | Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/ |
| CVE-2026-105630 | 8.7 HIGH | Plane: Stored XSS via SVG attachment served inline on the application origin (account take |
| CVE-2026-105632 | 8.7 HIGH | Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private |
| CVE-2026-104979 | 8.7 HIGH | Plane: Cross-tenant stored XSS in intake enables account takeover |
| CVE-2026-104976 | 8.7 HIGH | Plane: SSRF in Gitea OAuth |
| CVE-2026-104892 | 8.7 HIGH | Plane: Plaintext logging of API token |
| CVE-2026-104971 | 8.5 HIGH | Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEn |
| CVE-2026-104978 | 8.2 HIGH | Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acc |
| CVE-2026-104974 | 8.1 HIGH | Plane: Disabled User Auto-Reactivation on Login |
| CVE-2026-105634 | 8.1 HIGH | Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles |
| CVE-2026-104970 | 8.1 HIGH | Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthenticated calle |
| CVE-2026-104977 | 7.7 HIGH | Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is_blocked_ip ( |
| CVE-2026-104973 | 7.6 HIGH | Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery |
| CVE-2026-105628 | 7.6 HIGH | Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Static Asset End |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet