---
id: CVE-2026-104978
title: Plane is an open-source project management tool
summary: >-
  Plane is an open-source project management tool. Prior to 1.4.0, Plane's
  project invitation list endpoint is accessible to any authenticated user who
  knows the workspace slug and project ID, while the public project invitation
  join endpo…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-863
vendor: makeplane
product: plane
affected:
  - plane < 1.4.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T18:17:33.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104978'
references:
  - url: >-
      https://github.com/makeplane/plane/commit/14a4c22f94eac1582439e41112213f976c6a6cf7
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/pull/9308'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/releases/tag/v1.4.0'
    label: security-advisories@github.com
  - url: 'https://github.com/makeplane/plane/security/advisories/GHSA-g36h-p63v-g9c7'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T18:29:11.198Z'
---

## Overview

Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attacker can enumerate the invitation, register an account using the invited email without mailbox verification, and accept the invitation. The attacker-controlled account is then added to the target workspace and project. This issue is fixed in 1.4.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
