---
id: CVE-2026-104965
title: Plane is an open-source project management tool
summary: >-
  Plane is an open-source project management tool. Prior to 1.4.0, the
  issue-relation endpoint accepts issue UUIDs in the request body without
  validating that they belong to the caller's workspace. An authenticated user
  can create relation…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-639
vendor: makeplane
product: plane
affected:
  - plane < 1.4.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T18:17:31.887'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104965'
references:
  - url: >-
      https://github.com/makeplane/plane/commit/81d9873d7f1cf1d1252ed53c12dd33696be73a89
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/pull/9269'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/releases/tag/v1.4.0'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/security/advisories/GHSA-8cvv-8jh5-g6mj'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/security/advisories/GHSA-8cvv-8jh5-g6mj'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-05T17:49:30.511086Z'
ingestedAt: '2026-10-05T17:27:45.052Z'
---

## Overview

Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can create relations linking their own issues to issues in any other workspace on the instance, leaking issue metadata through activity events. This issue is fixed in 1.4.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
