๐Ÿ” CVE Alert

CVE-2026-104968

UNKNOWN 0.0

Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also exposes ProjectMember rows under the same condition. SearchEndpoint in apps/api/plane/app/views/search/base.py inherits BaseAPIView with only permission_classes = [IsAuthenticated] and performs no workspace-membership check. This issue is fixed in 1.4.0.

CWE CWE-862
Vendor makeplane
Product plane
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for makeplane plane

Be the first to know when new unknown vulnerabilities affecting makeplane plane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

makeplane / plane
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-32q3-mqpc-3mhv github.com: https://github.com/makeplane/plane/pull/9296 github.com: https://github.com/makeplane/plane/commit/28ae25b564351abaf8b36d4a3ba6d32f80fbf075 github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0