HTML Injection Vulnerability in Plane Project Management Tool by MakePlane
CVE-2026-104979

8.7HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-104979?

Plain is an open-source project management tool that allows users to create project issues. Versions prior to 1.4.0 are susceptible to an HTML injection vulnerability, where the IntakeIssuePublicViewSet.create method does not properly validate HTML content before writing it. This vulnerability permits any authenticated user, even those without workspace memberships, to insert malicious HTML. If a project member or viewer interacts with the corrupted link, the JavaScript within the inserted HTML can execute within their session, leading to potential exfiltration of sensitive information, such as long-lived API tokens. The vulnerability was addressed in version 1.4.0.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.