๐Ÿ” CVE Alert

CVE-2026-105641

CRITICAL 9.8

Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests โ€” session forgery and live-server auth bypass

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.

CWE CWE-798
Vendor makeplane
Product plane
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for makeplane plane

Be the first to know when new critical vulnerabilities affecting makeplane plane are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

makeplane / plane
< 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/makeplane/plane/security/advisories/GHSA-cmwv-pjmw-8483 github.com: https://github.com/makeplane/plane/pull/9291 github.com: https://github.com/makeplane/plane/commit/1acc69e816a9a8789032bf711aa9a3c12fcd285c github.com: https://github.com/makeplane/plane/releases/tag/v1.4.0