---
id: CVE-2026-105636
title: 'Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)'
summary: >-
  Plane is an open-source project management tool. Prior to 1.4.0, the webhook
  delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post()
  without allow_redirects=False and does not validate redirect targets.
  validate_url…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-918
vendor: makeplane
product: plane
affected:
  - plane < 1.4.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T18:02:53.127Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-105636'
references:
  - url: 'https://github.com/makeplane/plane/security/advisories/GHSA-mq87-52pf-hm3h'
    label: 'https://github.com/makeplane/plane/security/advisories/GHSA-mq87-52pf-hm3h'
  - url: 'https://github.com/makeplane/plane/pull/9163'
    label: 'https://github.com/makeplane/plane/pull/9163'
  - url: >-
      https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615
    label: >-
      https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615
  - url: 'https://github.com/makeplane/plane/releases/tag/v1.4.0'
    label: 'https://github.com/makeplane/plane/releases/tag/v1.4.0'
tags:
  - cve.org
ingestedAt: '2026-10-05T18:29:11.217Z'
---

## Overview

Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0.

## Affected

- `plane < 1.4.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
