CVE-2026-104893
Plane: Improper validation allows arbitrary modification of API token rate limits
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{token_id}/ allows the user to modify the token's allowed_rate_limit field without server-side validation or a maximum value. A user can raise the limit arbitrarily and bypass intended API rate-limiting controls, enabling high-volume automated requests, backend resource abuse, and possible resource exhaustion. This issue is fixed in 1.4.0.
| CWE | CWE-770 |
| Vendor | makeplane |
| Product | plane |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for makeplane plane
Be the first to know when new medium vulnerabilities affecting makeplane plane are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
makeplane / plane
< 1.4.0
References
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-xfgr-2x3f-g2cf github.com: https://github.com/makeplane/plane/pull/9148 github.com: https://github.com/makeplane/plane/commit/edf247541301e482f2688c63481464b671ec579d github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0