Stored XSS Vulnerability in Plane Project Management Tool by MakePlane
CVE-2026-105630
8.7HIGH
What is CVE-2026-105630?
An authenticated low-privilege member of the Plane project management tool can upload a malicious SVG file as an attachment. This file maintains an attacker-controlled Content-Type and, when downloaded, can execute embedded JavaScript within the application's security context. This behavior can lead to stored XSS attacks, enabling an attacker to compromise the session of any user, including administrators, who accesses the malicious link. This vulnerability has been addressed in version 1.4.0 of Plane.
Affected Version(s)
plane < 1.4.0
