๐Ÿ” CVE Alert

CVE-2026-104960

MEDIUM 6.5

Plane: Authorization bypass in workspace-scoped asset download endpoint exposes secret project file assets to non-project workspace users

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access to the asset's owning project. An authenticated user who belongs to the same workspace, is not a member of the victim's secret project, and knows the target asset UUID can receive a 302 redirect to a signed download URL. The intended project-scoped route for the same asset correctly returns 403. Confirmed affected project-bound asset types are ISSUE_ATTACHMENT, COMMENT_DESCRIPTION, PAGE_DESCRIPTION, and PROJECT_COVER. This bypass exposes private file content protected by the secret project boundary. This issue is fixed in 1.4.0.

CWE CWE-639 CWE-862
Vendor makeplane
Product plane
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for makeplane plane

Be the first to know when new medium vulnerabilities affecting makeplane plane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

makeplane / plane
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-wrrw-wvfv-67h7 github.com: https://github.com/makeplane/plane/pull/9372 github.com: https://github.com/makeplane/plane/commit/e63f0c3b3404d669ae05dd9050aab72292f87e5c github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0