Web Application Vulnerability in Plane Project Management Tool by Makeplane
CVE-2026-104973
7.6HIGH
What is CVE-2026-104973?
The Plane project management tool, prior to version 1.4.0, suffers from a vulnerability that compromises its server-side request forgery (SSRF) protections. The issue arises from inadequate validation of resolved IP addresses during webhook delivery, permitting malicious DNS rebinding attacks. This creates a potential vector for unauthorized access and exploitation. The vulnerability was specifically highlighted in the webhook handling components of the application, with a fix implemented in version 1.4.0.
Affected Version(s)
plane < 1.4.0
