Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-27705— Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch

Quick assessment

Affected
makeplane plane
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Plane是Plane开源的一个开源、自托管的项目规划工具。 Plane 1.2.2之前版本存在安全漏洞,该漏洞源于ProjectAssetEndpoint.patch()方法仅通过资产ID进行全局资产查找,而未验证资产是否属于URL路径中指定的工作区和项目,可能导致任何经过身份验证的用户通过猜测或枚举资产UUID来修改整个Plane实例中任何工作区或项目的资产属性和上传状态。

AI Predicted 7.5 Difficulty: Easy EPSS 0.39% · P31

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-27705

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoint.patch
Source: CVE Program / CVE List V5
Vulnerability Description
Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/asset/v2.py` (lines 579–593) performs a global asset lookup using only the asset ID (`pk`) via `FileAsset.objects.get(id=pk)`, without verifying that the asset belongs to the workspace and project specified in the URL path. This allows any authenticated user (including those with the GUEST role) to modify the `attributes` and `is_uploaded` status of assets belonging to any workspace or project in the entire Plane instance by guessing or enumerating asset UUIDs. Version 1.2.2 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5
Vulnerability Title
Plane 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Plane是Plane开源的一个开源、自托管的项目规划工具。 Plane 1.2.2之前版本存在安全漏洞,该漏洞源于ProjectAssetEndpoint.patch()方法仅通过资产ID进行全局资产查找,而未验证资产是否属于URL路径中指定的工作区和项目,可能导致任何经过身份验证的用户通过猜测或枚举资产UUID来修改整个Plane实例中任何工作区或项目的资产属性和上传状态。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
makeplane plane < 1.2.2 -

II. Public POCs for CVE-2026-27705

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-27705

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-27705

No comments yet


Leave a comment