CVE-2026-104968
Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also exposes ProjectMember rows under the same condition. SearchEndpoint in apps/api/plane/app/views/search/base.py inherits BaseAPIView with only permission_classes = [IsAuthenticated] and performs no workspace-membership check. This issue is fixed in 1.4.0.
| CWE | CWE-862 |
| Vendor | makeplane |
| Product | plane |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for makeplane plane
Be the first to know when new unknown vulnerabilities affecting makeplane plane are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
makeplane / plane
< 1.4.0
References
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-32q3-mqpc-3mhv github.com: https://github.com/makeplane/plane/pull/9296 github.com: https://github.com/makeplane/plane/commit/28ae25b564351abaf8b36d4a3ba6d32f80fbf075 github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0