Plane 是一款开源的项目管理工具。在 1.4.0 版本之前, 中的 webhook 投递任务在调用 时未设置 ,且未对重定向目标进行验证。虽然 会对原始 webhook URL 中的私有地址、回环地址、链路本地地址和保留地址进行拦截,但经过一次或多次重定向后最终访问的 URL 并未得到检查。任何具有创建工作区权限的用户,可以注册一个指向攻击者控制的公开端点的 webhook,该端点返回 302 重定向至内部地址。Plane 的后台工作进程随后会获取包括云元数据在内的内部资源,并将响应体存储到 中。攻击者可通过工
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105639 | 9.8 CRITICAL | Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation tok |
| CVE-2026-105641 | 9.8 CRITICAL | Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deploy |
| CVE-2026-105637 | 9.6 CRITICAL | Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-4 |
| CVE-2026-105638 | 9.1 CRITICAL | Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force |
| CVE-2026-105640 | 9.1 CRITICAL | Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab) |
| CVE-2026-105632 | 8.7 HIGH | Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private |
| CVE-2026-104892 | 8.7 HIGH | Plane: Plaintext logging of API token |
| CVE-2026-104966 | 8.7 HIGH | Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Modify, and Inj |
| CVE-2026-104976 | 8.7 HIGH | Plane: SSRF in Gitea OAuth |
| CVE-2026-104979 | 8.7 HIGH | Plane: Cross-tenant stored XSS in intake enables account takeover |
| CVE-2026-105630 | 8.7 HIGH | Plane: Stored XSS via SVG attachment served inline on the application origin (account take |
| CVE-2026-104968 | 8.7 HIGH | Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/ |
| CVE-2026-104971 | 8.5 HIGH | Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEn |
| CVE-2026-104978 | 8.2 HIGH | Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acc |
| CVE-2026-104970 | 8.1 HIGH | Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthenticated calle |
| CVE-2026-105634 | 8.1 HIGH | Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles |
| CVE-2026-104974 | 8.1 HIGH | Plane: Disabled User Auto-Reactivation on Login |
| CVE-2026-104977 | 7.7 HIGH | Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is_blocked_ip ( |
| CVE-2026-104973 | 7.6 HIGH | Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery |
| CVE-2026-105628 | 7.6 HIGH | Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Static Asset End |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet