Open-Source Project Management Tool Vulnerability in Plane
CVE-2026-105636
9.9CRITICAL
What is CVE-2026-105636?
The webhook delivery functionality within Plane, an open-source project management tool, contains a flaw that impacts how HTTP redirects are handled. Specifically, until version 1.4.0, a request intended for a webhook may redirect to a malicious external address, leading to the potential exposure of internal resources, such as cloud metadata. Since the final endpoint reached after redirection is not verified, an attacker can exploit this to capture sensitive information logged by the application. This vulnerability allows a user with workspace creation privileges to register a webhook that can be directed to an attacker-controlled data endpoint, making internal data accessible. The issue has been rectified in version 1.4.0.
Affected Version(s)
plane < 1.4.0
