๐Ÿ” CVE Alert

CVE-2026-104967

MEDIUM 5.4

Plane: Cross-workspace association destruction and issue mutation/read via unscoped queries in BulkDeleteIssuesEndpoint and SubIssuesEndpoint

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate on them without checking that the IDs belong to the caller's workspace and project. The permission decorator on each endpoint validates only that the caller is a member or administrator of the workspace and project named in the URL. BulkDeleteIssuesEndpoint can destroy CycleIssue and ModuleIssue associations belonging to foreign issues. SubIssuesEndpoint can re-parent foreign issues under an attacker-selected issue and return the foreign issues' metadata. This issue is fixed in 1.4.0.

CWE CWE-639
Vendor makeplane
Product plane
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for makeplane plane

Be the first to know when new medium vulnerabilities affecting makeplane plane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

makeplane / plane
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-6cw7-h92q-p9hg github.com: https://github.com/makeplane/plane/pull/9270 github.com: https://github.com/makeplane/plane/commit/ad73ca300ce35e4d4d231a933de6f20f8203f3df github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0