CVE-2026-104971
Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEndpoint Missing Authorization
CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th
Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0.
| CWE | CWE-639 CWE-862 |
| Vendor | makeplane |
| Product | plane |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for makeplane plane
Be the first to know when new high vulnerabilities affecting makeplane plane are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
makeplane / plane
< 1.4.0
References
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-p57q-8hh8-7fc7 github.com: https://github.com/makeplane/plane/pull/8885 github.com: https://github.com/makeplane/plane/pull/9288 github.com: https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b github.com: https://github.com/makeplane/plane/commit/ac11c3ef7939e31201fa92a17de106906025590f github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0