{"id":"CVE-2026-105639","title":"Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane","summary":"Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-200","CWE-287","CWE-639"],"vendor":"makeplane","product":"plane","affected":["plane < 1.4.0"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T18:10:35.787Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-105639","references":[{"url":"https://github.com/makeplane/plane/security/advisories/GHSA-4vj8-p63v-8p24","label":"https://github.com/makeplane/plane/security/advisories/GHSA-4vj8-p63v-8p24"},{"url":"https://github.com/makeplane/plane/pull/9297","label":"https://github.com/makeplane/plane/pull/9297"},{"url":"https://github.com/makeplane/plane/commit/6220ba990b2276a1a1979d1d5df68f650b8b47ad","label":"https://github.com/makeplane/plane/commit/6220ba990b2276a1a1979d1d5df68f650b8b47ad"},{"url":"https://github.com/makeplane/plane/releases/tag/v1.4.0","label":"https://github.com/makeplane/plane/releases/tag/v1.4.0"}],"tags":["cve.org"],"ingestedAt":"2026-10-05T18:29:11.209Z","slug":"CVE-2026-105639","body":"## Overview\n\nPlane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = \"all\", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target's email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker's initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0.\n\n## Affected\n\n- `plane < 1.4.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}