Field Injection Vulnerability in Plane Project Management Tool by Makeplane
CVE-2026-104956

5.3MEDIUM

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104956?

The Plane project management tool is susceptible to a field injection vulnerability due to the unauthenticated public issues endpoint, which improperly handles the 'group_by' and 'sub_group_by' query parameters. These parameters are passed directly to grouped paginators without validation, allowing an attacker to manipulate them. This can lead to unhandled exceptions, including FieldError or KeyError, resulting in HTTP 500 responses. Although the vulnerability does not directly expose sensitive column values, it does leave the application open to blind traversal attacks. The issue is resolved in version 1.4.0, which applies necessary validation to these parameters.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.