CVE-2026-105638Critical· 9.1▾ MidnightPlane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect cod…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply. The middleware stack also contains no Django-level rate limiter such as django-ratelimit, django-axes, or an IP-throttling middleware. This vulnerability is fixed in 1.4.0.
plane < 1.4.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105636Critical· 9.9Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
CVE-2026-105635High· 7.4Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token
CVE-2026-105637Critical· 9.6Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
CVE-2026-105639Critical· 9.8Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
CVE-2026-105640Critical· 9.1Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)
CVE-2026-105641Critical· 9.8Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass