Open-Source Project Management Tool Vulnerability in Plane
CVE-2026-105635

7.4HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105635?

The Plane project management tool has a vulnerability wherein the ProjectJoinEndpoint exposes sensitive data through the GET API endpoint, allowing unauthorized users to access full ProjectMemberInvite records. This includes sensitive information such as email addresses, tokens, and roles without authentication. Moreover, the POST endpoint does not properly validate invitation tokens, enabling potential attackers who know the invitation UUID to register an account and accept invitations without original notifications. This issue was addressed in version 1.4.0, enhancing the security of the tool.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.