Open-Source Project Management Tool Vulnerability in Plane
CVE-2026-105636

9.9CRITICAL

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105636?

The webhook delivery functionality within Plane, an open-source project management tool, contains a flaw that impacts how HTTP redirects are handled. Specifically, until version 1.4.0, a request intended for a webhook may redirect to a malicious external address, leading to the potential exposure of internal resources, such as cloud metadata. Since the final endpoint reached after redirection is not verified, an attacker can exploit this to capture sensitive information logged by the application. This vulnerability allows a user with workspace creation privileges to register a webhook that can be directed to an attacker-controlled data endpoint, making internal data accessible. The issue has been rectified in version 1.4.0.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.