CVE-2026-105637Critical· 9.6▾ MidnightPlane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, draft_issue_id, or project_id to an entity the attacker controls. Plane then treats the attacker's project as the new owner and provides a presigned download URL for the hijacked file. This issue is fixed in 1.4.0.
plane < 1.4.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105639Critical· 9.8Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
CVE-2026-105631High· 7.5Plane is an open-source project management tool
CVE-2026-105633High· 7.1Plane is an open-source project management tool
CVE-2026-105629High· 7.1Plane is an open-source project management tool
CVE-2026-104975High· 7.1Plane is an open-source project management tool
CVE-2026-104971High· 8.5Plane is an open-source project management tool