Plane 是一款开源的项目管理工具。在 1.4.0 版本之前,Plane 的 OAuth 头像同步流程通过服务器端 HTTP 请求从提供商用户数据中获取 ,未对内部 IP 地址进行验证,并且默认遵循重定向。攻击者可以提供重定向到仅限内部访问的资源(如元数据端点)的头像 URL,Plane 会将获取到的响应内容作为用户头像文件上传。该资源随后通过 路径暴露,从而导致可被利用来窃取内部获取的内容。此问题已在 1.4.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105636 | 9.9 CRITICAL | Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) |
| CVE-2026-105639 | 9.8 CRITICAL | Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation tok |
| CVE-2026-105641 | 9.8 CRITICAL | Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deploy |
| CVE-2026-105637 | 9.6 CRITICAL | Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-4 |
| CVE-2026-105638 | 9.1 CRITICAL | Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force |
| CVE-2026-105640 | 9.1 CRITICAL | Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) |
| CVE-2026-105630 | 8.7 HIGH | Plane: Stored XSS via SVG attachment served inline on the application origin (account take |
| CVE-2026-104892 | 8.7 HIGH | Plane: Plaintext logging of API token |
| CVE-2026-104966 | 8.7 HIGH | Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Modify, and Inj |
| CVE-2026-104976 | 8.7 HIGH | Plane: SSRF in Gitea OAuth |
| CVE-2026-104979 | 8.7 HIGH | Plane: Cross-tenant stored XSS in intake enables account takeover |
| CVE-2026-105632 | 8.7 HIGH | Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private |
| CVE-2026-104968 | 8.7 HIGH | Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/ |
| CVE-2026-104971 | 8.5 HIGH | Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEn |
| CVE-2026-104978 | 8.2 HIGH | Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acc |
| CVE-2026-104970 | 8.1 HIGH | Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthenticated calle |
| CVE-2026-105634 | 8.1 HIGH | Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles |
| CVE-2026-104974 | 8.1 HIGH | Plane: Disabled User Auto-Reactivation on Login |
| CVE-2026-104977 | 7.7 HIGH | Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is_blocked_ip ( |
| CVE-2026-104973 | 7.6 HIGH | Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet