Open-Source Project Management Tool Vulnerability in Plane by Makeplane
CVE-2026-104978
8.2HIGH
What is CVE-2026-104978?
The Plane project management tool has a security flaw where the project invitation list can be accessed by any authenticated user who knows the workspace slug and project ID. Additionally, the public project invitation join endpoint permits an invitation based solely on a provided email address. An attacker can leverage this by enumerating invitations aimed at unregistered email addresses, allowing them to create an account using the invitation email without verifying access to that mailbox. This results in the unauthorized account being added to the specified workspace and project. The issue has been addressed in version 1.4.0.
Affected Version(s)
plane < 1.4.0
