---
id: CVE-2026-104892
title: Plane is an open-source project management tool
summary: >-
  Plane is an open-source project management tool. Prior to 1.4.0,
  aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low
  privileges to steal user API keys and further escalate their privileges. This
  issue is fixed …
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-256
vendor: makeplane
product: plane
affected:
  - plane < 1.4.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T17:17:10.543'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104892'
references:
  - url: >-
      https://github.com/makeplane/plane/commit/edf247541301e482f2688c63481464b671ec579d
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/pull/9148'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/releases/tag/v1.4.0'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/security/advisories/GHSA-r5p8-cj3q-38cc'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-05T16:21:22.547515Z'
cvssSource: cna
ingestedAt: '2026-10-05T16:25:58.410Z'
---

## Overview

Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
