Webhook URL Validation Flaw in Plane Open-Source Project Management Tool
CVE-2026-30242
8.5HIGH
What is CVE-2026-30242?
The Plane open-source project management tool has a vulnerability in its webhook URL validation prior to version 1.2.3. The flaw allows users with the workspace ADMIN role to create webhooks that point to internal network addresses, such as 10.x.x.x, 172.16.x.x, and 192.168.x.x. This misconfiguration enables Server-Side Request Forgery (SSRF), where when webhook events are triggered, the server can make requests to those internal addresses and store the response. This potentially exposes sensitive information and allows unauthorized access to internal services.
Affected Version(s)
plane < 1.2.3
