Open-Source Project Management Tool Vulnerability in Plane
CVE-2026-105635
7.4HIGH
What is CVE-2026-105635?
The Plane project management tool has a vulnerability wherein the ProjectJoinEndpoint exposes sensitive data through the GET API endpoint, allowing unauthorized users to access full ProjectMemberInvite records. This includes sensitive information such as email addresses, tokens, and roles without authentication. Moreover, the POST endpoint does not properly validate invitation tokens, enabling potential attackers who know the invitation UUID to register an account and accept invitations without original notifications. This issue was addressed in version 1.4.0, enhancing the security of the tool.
Affected Version(s)
plane < 1.4.0
