CVE-2026-104966
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Summary
Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH /api/workspaces/{slug}/projects/{project_id}/estimates/{estimate_id}/, and can inject comments into an issue from another workspace through POST /api/workspaces/{slug}/projects/{project_id}/issues/{issue_id}/comments/. ProjectEntityPermission verifies membership in the workspace and project from the URL, but estimate_id and issue_id are fetched by primary key without confirming the same scope. The list, retrieve, and destroy handlers correctly scope their queries, demonstrating the inconsistency. This issue is fixed in 1.4.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| makeplane | plane | < 1.4.0 | affected |
Weaknesses
- CWE-639: CWE-639: Authorization Bypass Through User-Controlled Key
References
- https://github.com/makeplane/plane/security/advisories/GHSA-933r-rxg8-f3h2
- https://github.com/makeplane/plane/pull/9286
- https://github.com/makeplane/plane/commit/971c2aadb4e848d70676b4f58b94bc7992dfe5fc
- https://github.com/makeplane/plane/releases/tag/v1.4.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.