Vulnerability in Plane Project Management Tool Exposes Sensitive Secrets
CVE-2026-105641
9.8CRITICAL
What is CVE-2026-105641?
The Plane Project Management Tool, an open-source project management software, exhibits a significant vulnerability that exposes critical configuration secrets. In versions prior to 1.4.0, the manifests for community deployments contain hardcoded default values for SECRET_KEY and LIVE_SERVER_SECRET_KEY. These defaults remain active unless manually overridden by the operator. Consequently, if these keys are known, attackers can forge Django-signed values, potentially compromising user accounts or sessions. Additionally, knowledge of the LIVE_SERVER_SECRET_KEY can allow unauthorized access to live-service authentication, particularly in deployments that have not been secured. This vulnerability was addressed in version 1.4.0.
Affected Version(s)
plane < 1.4.0
