Open-Source Project Management Tool Vulnerability in Plane by MakePlane
CVE-2026-105637

9.6CRITICAL

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105637?

The Plane project management tool allows unauthorized access through a design flaw in its API, where a workspace Guest can exploit the ProjectBulkAssetEndpoint. By not enforcing proper project ID constraints, attackers can hijack asset UUIDs from different projects, misappropriating entity ownership. This vulnerability enables them to reassign issue IDs and gain presigned URLs for file downloads. The issue is addressed in version 1.4.0, enhancing security through improved access controls.

Affected Version(s)

plane < 1.4.0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.