Open Source Project Management Tool Vulnerability in Plane
CVE-2026-105633
7.1HIGH
What is CVE-2026-105633?
The Plane project management tool contains a vulnerability in its PATCH endpoint for the issue-attachment feature. The issue arises when an attacker can manipulate the issue_id in the URL to gain unauthorized access to modify attachments tied to other users' issues. The vulnerability occurs as the backend only matches certain database parameters—pk, workspace, and project_id—without verifying the issue_id from the URL. Consequently, this allows a malicious actor to transfer attachment ownership to themselves by modifying attachments that are pending upload and incorrectly sets the created_by attribute to the request's user. This vulnerability has been addressed in version 1.4.0.
Affected Version(s)
plane < 1.4.0
