Open Source Project Management Tool Vulnerability in Plane
CVE-2026-105633

7.1HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105633?

The Plane project management tool contains a vulnerability in its PATCH endpoint for the issue-attachment feature. The issue arises when an attacker can manipulate the issue_id in the URL to gain unauthorized access to modify attachments tied to other users' issues. The vulnerability occurs as the backend only matches certain database parameters—pk, workspace, and project_id—without verifying the issue_id from the URL. Consequently, this allows a malicious actor to transfer attachment ownership to themselves by modifying attachments that are pending upload and incorrectly sets the created_by attribute to the request's user. This vulnerability has been addressed in version 1.4.0.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.