๐Ÿ” CVE Alert

CVE-2026-104892

UNKNOWN 0.0

Plane: Plaintext logging of API token

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.

CWE CWE-256
Vendor makeplane
Product plane
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for makeplane plane

Be the first to know when new unknown vulnerabilities affecting makeplane plane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

makeplane / plane
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-r5p8-cj3q-38cc github.com: https://github.com/makeplane/plane/pull/9148 github.com: https://github.com/makeplane/plane/commit/edf247541301e482f2688c63481464b671ec579d github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0