Plane 是一款开源的项目管理工具。在 1.4.0 版本之前,Plane 仅对 GITEA_HOST 的 URL 方案(scheme)进行验证,而未拒绝那些解析到私有或内部 IP 地址的主机。在 Gitea OAuth 流程中涉及的四个出站请求均源自该未经验证的主机,且这些请求未调用 validate_url() 函数进行额外验证。此外,avatar_url 取自 Gitea 用户的个人资料,用户可在其中配置外部头像 URL。当管理员为合法的 Gitea 实例启用 OAuth 认证后,Gitea 用户可将内部 U
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105636 | 9.9 CRITICAL | Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) |
| CVE-2026-105639 | 9.8 CRITICAL | Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation tok |
| CVE-2026-105641 | 9.8 CRITICAL | Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deploy |
| CVE-2026-105637 | 9.6 CRITICAL | Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-4 |
| CVE-2026-105638 | 9.1 CRITICAL | Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force |
| CVE-2026-105640 | 9.1 CRITICAL | Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) |
| CVE-2026-105630 | 8.7 HIGH | Plane: Stored XSS via SVG attachment served inline on the application origin (account take |
| CVE-2026-104892 | 8.7 HIGH | Plane: Plaintext logging of API token |
| CVE-2026-104966 | 8.7 HIGH | Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Modify, and Inj |
| CVE-2026-104979 | 8.7 HIGH | Plane: Cross-tenant stored XSS in intake enables account takeover |
| CVE-2026-105632 | 8.7 HIGH | Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private |
| CVE-2026-104968 | 8.7 HIGH | Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/ |
| CVE-2026-104971 | 8.5 HIGH | Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEn |
| CVE-2026-104978 | 8.2 HIGH | Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acc |
| CVE-2026-104970 | 8.1 HIGH | Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthenticated calle |
| CVE-2026-105634 | 8.1 HIGH | Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles |
| CVE-2026-104974 | 8.1 HIGH | Plane: Disabled User Auto-Reactivation on Login |
| CVE-2026-104977 | 7.7 HIGH | Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is_blocked_ip ( |
| CVE-2026-104973 | 7.6 HIGH | Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery |
| CVE-2026-105628 | 7.6 HIGH | Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Static Asset End |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet