Open-Source Project Management Tool Vulnerability in Plane by MakePlane
CVE-2026-105637
9.6CRITICAL
What is CVE-2026-105637?
The Plane project management tool allows unauthorized access through a design flaw in its API, where a workspace Guest can exploit the ProjectBulkAssetEndpoint. By not enforcing proper project ID constraints, attackers can hijack asset UUIDs from different projects, misappropriating entity ownership. This vulnerability enables them to reassign issue IDs and gain presigned URLs for file downloads. The issue is addressed in version 1.4.0, enhancing security through improved access controls.
Affected Version(s)
plane < 1.4.0
