Stored XSS Vulnerability in Plane Project Management Tool by MakePlane
CVE-2026-105630

8.7HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105630?

An authenticated low-privilege member of the Plane project management tool can upload a malicious SVG file as an attachment. This file maintains an attacker-controlled Content-Type and, when downloaded, can execute embedded JavaScript within the application's security context. This behavior can lead to stored XSS attacks, enabling an attacker to compromise the session of any user, including administrators, who accesses the malicious link. This vulnerability has been addressed in version 1.4.0 of Plane.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.