Server-Side Request Forgery Vulnerability in Plane Project Management Tool
CVE-2026-104977

7.7HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104977?

Plane, an open-source project management tool by Makeplane, contains a serious server-side request forgery (SSRF) vulnerability in versions before 1.4.0. The issue primarily affects the link unfurling feature for work items. Authenticated users can potentially manipulate the server to fetch internal resources, such as cloud metadata located at 169.254.169.254, thereby exposing sensitive data. The initial fix from previous advisories was incomplete in the v1.3.1 release but was ultimately resolved in version 1.4.0. Developers are encouraged to update to the latest version to mitigate risk.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.