Remote Code Execution Vulnerability in Plane Open-source Project Management Tool
CVE-2026-104976

8.7HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104976?

The Plane open-source project management tool is vulnerable to a significant issue where it improperly validates the GITEA_HOST setting. Prior to version 1.4.0, up to four outbound requests in the Gitea OAuth flow were derived from an unvalidated host, potentially allowing malicious users to exploit internal or private IP addresses. Furthermore, the avatar_url can be sourced from user profiles, enabling adversaries to set an internal URL as an avatar and trigger the application to make unauthorized requests to those internal targets. This flaw compromises the application's overall security, allowing for remote execution and data exposure risks.

Affected Version(s)

plane < 1.4.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.