CVE-2026-104956Medium· 5.3▾ SunlitPlane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts group_by and sub_group_by query parameters and passes them without an allowlist to grouped paginators, where they are use…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts group_by and sub_group_by query parameters and passes them without an allowlist to grouped paginators, where they are used as ORM field names by F(field), .values(field), .order_by(field), and Window partition_by operations. An anonymous attacker can supply arbitrary field paths that trigger an unhandled FieldError or KeyError and an HTTP 500 response, or force the ORM to resolve __-separated relational paths as a blind traversal oracle. This is the same field-name injection class addressed by earlier order_by sanitization, but that remediation left group_by and sub_group_by unvalidated. The issue does not directly disclose column values because issue_group_values() returns an empty list for unknown fields, the result projection uses a fixed required_fields list, and the subgrouped path raises KeyError before serialization. This issue is fixed in 1.4.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105636Critical· 9.9Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
CVE-2026-105635High· 7.4Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token
CVE-2026-105637Critical· 9.6Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
CVE-2026-105638Critical· 9.1Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force
CVE-2026-105639Critical· 9.8Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
CVE-2026-105640Critical· 9.1Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)