CVE-2026-104892
Plane: Plaintext logging of API token
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.
| CWE | CWE-256 |
| Vendor | makeplane |
| Product | plane |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for makeplane plane
Be the first to know when new unknown vulnerabilities affecting makeplane plane are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
makeplane / plane
< 1.4.0
References
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-r5p8-cj3q-38cc github.com: https://github.com/makeplane/plane/pull/9148 github.com: https://github.com/makeplane/plane/commit/edf247541301e482f2688c63481464b671ec579d github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0