Information Disclosure in Plane Project Management Tool
CVE-2026-104963
What is CVE-2026-104963?
The Plane project management tool, before version 1.4.0, is susceptible to an information disclosure vulnerability. This flaw allows any authenticated member of a workspace, including those with guest access to a single project, to retrieve sensitive details about private projects through specific API endpoints without proper access controls. The affected API endpoints include GET /api/workspaces/{slug}/cycles/ and GET /api/workspaces/{slug}/modules/, which expose critical data such as project names, descriptions, sprint dates, issue counts, progress snapshots, external integration IDs, and member lists. The inconsistency in access control checks between these endpoints and their counterparts poses a significant risk to user privacy and project security. This issue has been addressed in version 1.4.0.
Affected Version(s)
plane < 1.4.0
