---
id: CVE-2026-104971
title: Plane is an open-source project management tool
summary: >-
  Plane is an open-source project management tool. Prior to 1.4.0,
  DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the
  caller's workspace, allowing cross-workspace asset duplication.
  WorkspaceFileAssetEndpoint and …
severity: high
cvss: 8.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-639
  - CWE-862
vendor: makeplane
product: plane
affected:
  - plane < 1.4.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T18:17:32.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104971'
references:
  - url: >-
      https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b
    label: security-advisories@github.com
  - url: >-
      https://github.com/makeplane/plane/commit/ac11c3ef7939e31201fa92a17de106906025590f
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/pull/8885'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/pull/9288'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/releases/tag/v1.4.0'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/security/advisories/GHSA-p57q-8hh8-7fc7'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T17:27:45.058Z'
---

## Overview

Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
