Webhook URL Validation Flaw in Plane Open-Source Project Management Tool
CVE-2026-30242

8.5HIGH

Key Information:

Vendor

Makeplane

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2026-30242?

The Plane open-source project management tool has a vulnerability in its webhook URL validation prior to version 1.2.3. The flaw allows users with the workspace ADMIN role to create webhooks that point to internal network addresses, such as 10.x.x.x, 172.16.x.x, and 192.168.x.x. This misconfiguration enables Server-Side Request Forgery (SSRF), where when webhook events are triggered, the server can make requests to those internal addresses and store the response. This potentially exposes sensitive information and allows unauthorized access to internal services.

Affected Version(s)

plane < 1.2.3

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.