Remote Code Execution Vulnerability in Plane Open-source Project Management Tool
CVE-2026-104976
8.7HIGH
What is CVE-2026-104976?
The Plane open-source project management tool is vulnerable to a significant issue where it improperly validates the GITEA_HOST setting. Prior to version 1.4.0, up to four outbound requests in the Gitea OAuth flow were derived from an unvalidated host, potentially allowing malicious users to exploit internal or private IP addresses. Furthermore, the avatar_url can be sourced from user profiles, enabling adversaries to set an internal URL as an avatar and trigger the application to make unauthorized requests to those internal targets. This flaw compromises the application's overall security, allowing for remote execution and data exposure risks.
Affected Version(s)
plane < 1.4.0
