HTML Injection Vulnerability in Plane Project Management Tool by MakePlane
CVE-2026-104979
8.7HIGH
What is CVE-2026-104979?
Plain is an open-source project management tool that allows users to create project issues. Versions prior to 1.4.0 are susceptible to an HTML injection vulnerability, where the IntakeIssuePublicViewSet.create method does not properly validate HTML content before writing it. This vulnerability permits any authenticated user, even those without workspace memberships, to insert malicious HTML. If a project member or viewer interacts with the corrupted link, the JavaScript within the inserted HTML can execute within their session, leading to potential exfiltration of sensitive information, such as long-lived API tokens. The vulnerability was addressed in version 1.4.0.
Affected Version(s)
plane < 1.4.0
