CVE-2026-105641Critical· 9.8▾ MidnightPlane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET_KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.
plane < 1.4.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105636Critical· 9.9Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
CVE-2026-105635High· 7.4Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthorized Project Join Without Token
CVE-2026-105637Critical· 9.6Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
CVE-2026-105638Critical· 9.1Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute force
CVE-2026-105639Critical· 9.8Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
CVE-2026-105640Critical· 9.1Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)