Security: makeplane/plane
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in PlaneGHSA-4vj8-p63v-8p24 published
Aug 3, 2026 by mguptahubCritical -
SSRF via HTTP redirect in webhook delivery (allow_redirects not set)GHSA-mq87-52pf-hm3h published
Aug 3, 2026 by mguptahubCritical -
Account Takeover via Unverified OAuth Email Match (Gitea, self-managed GitLab)GHSA-7j95-vh8g-f365 published
Aug 3, 2026 by mguptahubCritical -
Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of GHSA / CVE-2026-46558)GHSA-r2hw-fff3-pjwp published
Aug 3, 2026 by mguptahubCritical -
Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP brute forceGHSA-mqjv-rwgv-4gxq published
Aug 3, 2026 by mguptahubCritical -
Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypassGHSA-cmwv-pjmw-8483 published
Aug 3, 2026 by mguptahubCritical -
Full Read Server-Side Request Forgery (SSRF) in Favicon Fetching using RedirectionGHSA-9fr2-pprw-pp9j published
Apr 9, 2026 by sriramveeraghantaHigh -
Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspacesGHSA-qw87-v5w3-6vxx published
May 15, 2026 by sriramveeraghantaHigh -
ORM Field Reference Injection via `segment` Parameter in Saved AnalyticsGHSA-93x3-ghh7-72j3 published
May 15, 2026 by sriramveeraghantaModerate -
IDOR: Cross-Project Issue Date Modification via Bulk Update EndpointGHSA-4q54-h4x9-m329 published
Apr 7, 2026 by sriramveeraghantaModerate