plane vulnerabilities
CVEs whose affected-version data names the plane package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-86174Medium· 4.3Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint
Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to …
▾ Sunlitmakeplane · planeEPSS 0.20%via NVD
CVE-2026-27949Low· 2.0Plane is an an open-source project management tool
Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when …
▾ Sunlitplane · planeEPSS 0.17%via NVD