Server-Side Request Forgery Vulnerability in Plane Project Management Tool
CVE-2026-104977
7.7HIGH
What is CVE-2026-104977?
Plane, an open-source project management tool by Makeplane, contains a serious server-side request forgery (SSRF) vulnerability in versions before 1.4.0. The issue primarily affects the link unfurling feature for work items. Authenticated users can potentially manipulate the server to fetch internal resources, such as cloud metadata located at 169.254.169.254, thereby exposing sensitive data. The initial fix from previous advisories was incomplete in the v1.3.1 release but was ultimately resolved in version 1.4.0. Developers are encouraged to update to the latest version to mitigate risk.
Affected Version(s)
plane < 1.4.0
