Open Redirect Vulnerability in Plane Project Management Software by MakePlane
CVE-2025-62716
8.1HIGH
What is CVE-2025-62716?
An open redirect vulnerability in Plane's '?next_path' query parameter allows attackers to introduce arbitrary schemes, including 'javascript:', which are forwarded to router.push. This flaw enables execution of unauthorized JavaScript code in the browser of an unsuspecting user. The vulnerability does not require user authentication, posing significant risks such as information disclosure and unauthorized elevation of privileges. The issue was addressed in version 1.1.0.
Affected Version(s)
plane < 1.1.0
